Hi, I've follow your link but it only applies to windows 2000 server. Beside, I'd already try "Logon Locally" (I won't use Deny logon locally because it will reverse "Logon Locally" and prevent local administrator to logon) before I sent email to this mlist. I also add domain user via control panel but they all got no use. :( I still hope that samba may saves me. :D
Kind regards, On Tue, Mar 3, 2009 at 5:37 PM, Wolfgang Ratzka <[email protected]>wrote: > I have a pc (already joinned the samba domain 'DOMAIN') that I want to keep >> off other domain users but user DOMAIN\mark and DOMAIN\thomas whilst >> letting >> both of them to logon freely to other computers. >> > > You might want to manipulate the SeInteractiveLogonRight and possibly > SeNetworkLogonRight on the PC itself. Have a look at > http://support.microsoft.com/kb/279664 > > Two hints: > - You might want to define a group and assign rights to the group > instead of single users. > - Avoid locking out yourself and the admins. > > Kind regards, > > -- > Wolfgang Ratzka Phone: +49 6421 2823531 FAX: +49 6421 2826994 > Uni Marburg, HRZ, Hans-Meerwein-Str., D-35032 Marburg, Germany > -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba
