The AD domain prohibits domain users from logging in using local accounts.

Disallow domain users from logging in using local accounts

1. Users are prohibited from logging in using local accounts. What is prohibited is setting computer permissions, not account permissions.

  • Open Active Directory Users and Computers

WindowsServer2019AD domain, prohibit domain users from using local accounts to log in_domain users

  • Find computers. Under computers are all computers that have been added to the domain.

    WindowsServer2019AD domain, prohibit domain users from using local accounts to log in_Domain User_02

  • Add the computer that needs to prohibit local account login to the created organizational unit (drag the computer to the created organizational unit)

  • WindowsServer2019AD domain, prohibit domain users from using local accounts to log in_Domain User_03

2. Open Group Policy Management

  • WindowsServer2019AD domain, prohibit domain users from using local accounts to log in_Active Directory_04
  • Select Forest – Domain – Organizational Unit
  • WindowsServer2019AD domain, prohibit domain users from using local accounts to log in_Domain User_05
  • Right-click on the organizational unit and select Create GPO in this domain and link here
  • WindowsServer2019AD domain, domain users are prohibited from logging in using local accounts_Domain users are prohibited from logging in locally_06
  • give a name
  • WindowsServer2019AD domain, prohibit domain users from using local accounts to log in_AD domain_07
  • Right-click on the GPO you just created and edit
  • WindowsServer2019AD domain, prohibit domain users from using local accounts to log in_Domain User_08
  • In the opened Group Policy Management Editor, open Computer Configuration – Policies – Windows Settings – Security Settings – Local Policies – User Rights Assignment – ​​Deny local logon
  • WindowsServer2019AD domain, prohibit domain users from using local accounts to log in_AD domain_09
  • In Deny local login, add the local administrator account, local account group, local account and management group member group in sequence.
  • WindowsServer2019AD domain, prohibit domain users from logging in using local accounts_Prohibit domain users from logging in locally_10

3. The setting of prohibiting domain users from using local accounts to log in is completed. If you use local accounts to log in on domain users’ computers, you will be prompted that the login method you are trying is not allowed.

WindowsServer2019AD domain, prohibit domain users from logging in using local accounts_Prohibit domain users from logging in locally_11

Guess you like

Origin blog.csdn.net/qq_23435961/article/details/129145662