You could create a Group Policy and under Computer Configuration | Windows Settings | Security Settings | Local Policies | User Rights Assessment you can enable the Deny Logon Locally.
I hope that helps. - - Pete Mantai "Matt Andreko" To: <[EMAIL PROTECTED]> <mandreko@ori cc: .net> Fax to: Subject: restrict local users totally 12/31/2001 02:10 PM I am trying to setup a test domain so that I can learn more about active directory and such. I am beginning to get it going. On the domain controller, there won't be any local users, because it's a domain controller. However, all the workstations connecting to it can have local or domain users. Is there a way to disable local users on the workstations, to FORCE the users to log on to the domain? -- Matt Andreko