Restrict computer logons to a group of users

mara2021 996 Reputation points
2021-10-20T16:49:49.777+00:00

I have an OU called Test Desktops. I have test workstations in this OU. I created and linked a GPO to this OU called Restrict test allowed logons. Created a group with users allowed to logon to the test workstations. Added this group to the allow logon locally in the computer configuration settings along with administrators and domain admins. disabled "do not require ctrl+Alt+del" setting. security filtering has authenticated users and domain users (tried with and without domain users).

We tested with a domain user not in the allowed group. The test user is able to login. I have run GPupdate /f. shut down the workstation. I run gpresults. it states that the GPO is applied. If I look at the local security settings on the workstation, allow logon locally is not changed. Any help will be appreciated. Thank you.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,740 questions
0 comments No comments
{count} votes

Accepted answer
  1. cthivierge 4,056 Reputation points
    2021-10-20T17:14:45.853+00:00

    If you run "rsop.msc" on the workstation, you should see if the GPO settings are applied or not.

    Have you looked into the group policy logs in the Event Viewer to see if there is some errors ?
    Applications and Services Logs / Microsoft / Windows / GroupPolicy

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. mara2021 996 Reputation points
    2021-10-20T17:52:28.727+00:00

    Thank you for the suggestion. I had several workstations in the OU. I discovered that only one workstation had an issue. I ran RSOP and discovered that the allow logon locally was greyed out. Further investigation showed that their was a deny logon for another group. The workstation having the issue was recently added to the OU from another OU.