Locking Down Users

Discussion in 'Networks' started by Mr.Cheeks, Dec 19, 2006.

  1. zimbo
    Honorary Member

    zimbo Petabyte Poster

    5,215
    99
    181
    guess what you not the only one struggling!

    Here is another tip - try it i maybe right

    open active directory
    create a security group (pete will be proud now! :biggrin )
    make the clients members of that group
    create the policy
    then under security filter add that group

    worked for me! just not sure how! :(
     
    Certifications: B.Sc, MCDST & MCSA
    WIP: M.Sc - Computer Forensics
  2. Mr.Cheeks

    Mr.Cheeks 1st ever Gold Member! Gold Member

    5,373
    89
    190
    something about filtering :oops:

    Code:
    
    C:\Documents and Settings\Administrator>gpresult
    
    Microsoft (R) Windows (R) Operating System Group Policy Result tool v2
    Copyright (C) Microsoft Corp. 1981-2001
    
    Created On 20/12/2006 at 10:17:08
    
    
    RSOP data for VMWARE\Administrator on WIN2K3AD-VMW : Logging Mode
    ------------------------------------------------------------------
    
    OS Type:                     Microsoft(R) Windows(R) Server 2003, Ente
    tion
    OS Configuration:            Primary Domain Controller
    OS Version:                  5.2.3790
    Terminal Server Mode:        Remote Administration
    Site Name:                   Default-First-Site
    Roaming Profile:
    Local Profile:               C:\Documents and Settings\Administrator
    Connected over a slow link?: No
    
    
    COMPUTER SETTINGS
    ------------------
        CN=WIN2K3AD-VMW,OU=Domain Controllers,DC=vmware,DC=local
        Last time Group Policy was applied: 20/12/2006 at 10:14:30
        Group Policy was applied from:      win2k3ad-vmw.vmware.local
        Group Policy slow link threshold:   500 kbps
        Domain Name:                        VMWARE
        Domain Type:                        Windows 2000
    
        Applied Group Policy Objects
        -----------------------------
            Default Domain Controllers Policy
            Default Domain Policy
    
        The following GPOs were not applied because they were filtered out
        ------------------------------------------------------------------
            User Group Lock Down
                Filtering:  Not Applied (Empty)
    
            Local Group Policy
                Filtering:  Not Applied (Empty)
    
        The computer is a part of the following security groups
        -------------------------------------------------------
            BUILTIN\Administrators
            Everyone
            BUILTIN\Users
            BUILTIN\Pre-Windows 2000 Compatible Access
            Windows Authorization Access Group
            NT AUTHORITY\NETWORK
            NT AUTHORITY\Authenticated Users
            This Organization
            WIN2K3AD-VMW$
            Domain Controllers
            NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS
    
    
    USER SETTINGS
    --------------
        CN=Administrator,CN=Users,DC=vmware,DC=local
        Last time Group Policy was applied: 20/12/2006 at 10:14:30
        Group Policy was applied from:      win2k3ad-vmw.vmware.local
        Group Policy slow link threshold:   500 kbps
        Domain Name:                        VMWARE
        Domain Type:                        Windows 2000
    
        Applied Group Policy Objects
        -----------------------------
            User Group Lock Down
            Default Domain Policy
    
        The following GPOs were not applied because they were filtered out
        ------------------------------------------------------------------
            Local Group Policy
                Filtering:  Not Applied (Empty)
    
        The user is a part of the following security groups
        ---------------------------------------------------
            Domain Users
            Everyone
            BUILTIN\Administrators
            BUILTIN\Users
            BUILTIN\Pre-Windows 2000 Compatible Access
            NT AUTHORITY\INTERACTIVE
            NT AUTHORITY\Authenticated Users
            This Organization
            LOCAL
            Schema Admins
            Domain Admins
            Enterprise Admins
            Group Policy Creator Owners
    
    C:\Documents and Settings\Administrator>
    
    
     
  3. Boycie
    Honorary Member

    Boycie Senior Beer Tester

    6,281
    85
    174
    Cheeks,

    That's the output from the DC. Can you do the same from the Client please?

    Si
     
    Certifications: MCSA 2003, MCDST, A+, N+, CTT+, MCT
  4. AJ

    AJ 01000001 01100100 01101101 01101001 01101110 Administrator

    6,897
    182
    221
    Under the security settings (I am doing this from memory, so sorry if I miss anything) you need to have the Group "Authenticated Users" or if you are applying the settings to a security group must have READ access to the policy, otherwise they can't use the settings.
     
    Certifications: MCSE, MCSA (messaging), ITIL Foundation v3
    WIP: Breathing in and out, but not out and in, that's just wrong
  5. Mr.Cheeks

    Mr.Cheeks 1st ever Gold Member! Gold Member

    5,373
    89
    190
    @ Zimbo - there are already part of the security group Global for Domain Users

    @ Boyce - command not recognised
     
  6. Boycie
    Honorary Member

    Boycie Senior Beer Tester

    6,281
    85
    174
     
    Certifications: MCSA 2003, MCDST, A+, N+, CTT+, MCT
  7. Mr.Cheeks

    Mr.Cheeks 1st ever Gold Member! Gold Member

    5,373
    89
    190
    Yes i can from both way
     
  8. Boycie
    Honorary Member

    Boycie Senior Beer Tester

    6,281
    85
    174
    and you succesfully joined the domain? Have you retried, incase of spelling error?

    Si
     
    Certifications: MCSA 2003, MCDST, A+, N+, CTT+, MCT
  9. Mr.Cheeks

    Mr.Cheeks 1st ever Gold Member! Gold Member

    5,373
    89
    190
    yes - i created accounts on the DC, ran gpupdate and logged in using those accounts on the "client".

    gpresult

    edit: did i need to install wsus
     
  10. Boycie
    Honorary Member

    Boycie Senior Beer Tester

    6,281
    85
    174
    Cheeks,

    Is there anything in the client event logs? From memory, if you run the gpresult command from a workgroup machine you receive a message saying that their is no domain information availible but the point being the command is installed by default.

    Si
     
    Certifications: MCSA 2003, MCDST, A+, N+, CTT+, MCT
  11. Mr.Cheeks

    Mr.Cheeks 1st ever Gold Member! Gold Member

    5,373
    89
    190
    This is the application log error message (quite a few of the same). cant access as the required priveledge is not held by the client :blink

    Code:
    Windows cannot determine the user or computer name. Return value (1722). 
    
    edit: i done what its said on mskb (remove from domain and into workgroup > reboot > join domain) and still never worked
     
  12. AJ

    AJ 01000001 01100100 01101101 01101001 01101110 Administrator

    6,897
    182
    221
    Are you just running gpupdate.exe from the commenad prompt. You should use gpupdate.exe /force /boot

    The boot bit isn't really necessary but I always find that a reboot helps.
     
    Certifications: MCSE, MCSA (messaging), ITIL Foundation v3
    WIP: Breathing in and out, but not out and in, that's just wrong
  13. Mr.Cheeks

    Mr.Cheeks 1st ever Gold Member! Gold Member

    5,373
    89
    190
    i tried that and still nowt...

    you guys are gonna kill me next week.
     

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.