I can’t think of a group policy that would override this.  Is it possible that when you checked the user account after you had made the changes that you hadn’t waited for the replication to take place?  You may have made the changes on DC1, and when the user account attempted to log in, it may have authenticated against a DC other than DC1.

 

~Ben

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Timothy Foster
Sent: Thursday, July 13, 2006 1:03 PM
To: [email protected]
Subject: [ActiveDir] Log On To...

 

On the Account tab of the User Properties window in ADUC there is a 'Log On To...' button which - I thought - limited the user's ability to logon to only workstations specified.

 

I applied restrictions to an account in our domain and they did not work.  In other words, the restricted account was able to logon to a workstation not specified in the list.

 

What did I miss?  Is there a group policy setting that may be over-riding the setting?  How do I go about troubleshooting this?

 

Thank in advance.

 

Tim

 

 

 

Reply via email to