similar to: Avoid user logon

Displaying 20 results from an estimated 40000 matches similar to: "Avoid user logon"

2015 Aug 20
2
Avoid user logon
On 8/20/2015 11:34 AM, Marc Muehlfeld wrote: > Hello, > > Am 19.08.2015 um 23:24 schrieb shacky: >> How can I avoid a user or a set of users of a Samba 4 Domain Controller to >> login on Windows clients or let them to only login on some specific clients? >> Thank you very much! > You can lock an account to a set of defined workstations in the user > object, or more
2015 Aug 20
0
Avoid user logon
Hello, Am 19.08.2015 um 23:24 schrieb shacky: > How can I avoid a user or a set of users of a Samba 4 Domain Controller to > login on Windows clients or let them to only login on some specific clients? > Thank you very much! You can lock an account to a set of defined workstations in the user object, or more global via GPO. See
2014 Dec 21
4
Is there have simplest way to make domain users which in remote desktop group can remote/local logon the workstation ?
On Sat, Dec 20, 2014 at 4:15 PM, Tim <rintimtim at gmx.net> wrote: > Then I would do it with a group policy. Have a look right here: > http://technet.microsoft.com/en-us/library/ee791928(v=WS.10).aspx > > Remind that you leave the default policies untouched. Create a new GPo and > link it to your desired OU. > After put domain users in the remote destop group in the DC,
2016 Sep 19
2
Upgraded SAMBA4 DC's, now no logon scripts
On Mon, 2016-09-19 at 20:57 +0200, Marc Muehlfeld wrote: > > Logon scripts assigned to a user do not execute when the user logs > > on; it did before the upgrade. > * What kind of upgrade are you talking about? > NT4 to AD? (migration) > x.y to 4.2? AD 4.0.21 -> 4.2.x This worked prior to the upgrade. > * Is this an PDC or DC? They are DCs. > * Where have you
2015 Feb 27
3
Is Server-side GPO Configuration possible? (for logon script)
On 26/02/15 16:54, Marc Muehlfeld wrote: > Hello John, > > Am 26.02.2015 um 12:17 schrieb John: >> Is it possible to make GPO changes from the server (i.e. without using >> Windows) ? > No. There's no tool for *nix, to edit GPOs. At least I've never seen > one. :-) > > > Regards, > Marc > Shame, that. But I kind of expected that to be the answer.
2015 May 19
3
Deny login for a specific user in a specific machine in a samba domain
PDC. I'm using samba 3, I need scripts to apply GPO? Citando Tim <lists at kiuni.de>: > PDC or ADDC? You could achieve this with a GPO. > > Regards > Tim > ? > Am 18. Mai 2015 18:20:28 MESZ, schrieb Rodrigo Abrantes Antunes > <rodrigoantunes at pelotas.ifsul.edu.br>: >> Hi, I have samba as a PDC and I need to deny login for a specific user >> in
2015 May 20
3
Deny login for a specific user in a specific machine in a samba domain
Well, samba 3 can't act as AD DC, so I guess the only way I can achieve this remotely is setting this in registry using a login script. How can I set this in registry? There Isn't something that automates the creation of scripts that change policies by registry? Citando Marc Muehlfeld <mmuehlfeld at samba.org>: > Hello Rodrigo, > > Am 19.05.2015 um 13:40 schrieb Rodrigo
2018 Mar 27
2
Share users across domains
And how can I use these gpos?  I need to configure a gpo that pevent student login in each administrative machine?  Citando Waishon <waishon009 at gmail.com>: > Hi, >   > I would use one domain and some groups. So you put your Students > in the "students" group and the administratives in the "admin". >   > Then simply create two OUs, one for
2017 Apr 03
6
GPO administration right on the station for ordinary user
Good morning people, I need a help with a gpo to give administration right only on the workstation for a normal user. I tried 3 tutorials I found on google plus none worked. How do you do when you need an ordinary user to have administration right only on the workstation? If you have a tutorial that is running in version 4.5.5 and can make it available thank you very much. Regards,
2015 Feb 26
2
Is Server-side GPO Configuration possible? (for logon script)
Is it possible to make GPO changes from the server (i.e. without using Windows) ? I would like to include some configuration in my build-out script and wonder if it is possible. Specifically, I am trying to provide a logon script. Here's what I know. 1. I can identify the correct GPO GUID object using "samba-tool gpo listall" or with something like this $ ldbsearch -H
2015 May 18
3
Deny login for a specific user in a specific machine in a samba domain
Hi, I have samba as a PDC and I need to deny login for a specific user in a specific machine. How can I achieve that? -- Rodrigo Abrantes Antunes Instituto Federal Sul-rio-grandense
2015 Feb 27
2
Is Server-side GPO Configuration possible? (for logon script)
On 27/02/15 14:34, Marc Muehlfeld wrote: > Am 27.02.2015 um 09:42 schrieb John: >> Shame, that. But I kind of expected that to be the answer. >> >> I guess the next best thing is to script it on Windows. Provide a script >> (perhaps in sysvol/scripts) that can be run on a windows box as a domain >> admin to finish the configuration. I guess this would be a Windows
2017 Oct 19
3
Best practice for creating an RO LDAP User in AD...
Caming from Samba in NT mode with OpenLDAP backend i've created a bunch of ''things'' (apps, web tools, ...; but also printers and so on) that rely on reading ''public'' data in LDAP. With OpenLDAP ''public'' was a easy concept: anonymous access was the default, and ACL protect more sensitive data (mostly, passwords). Now i've to redo some
2015 Aug 28
2
Active Directory clients in DMZ
Hi. I have two Samba 4 Domain Controller in the LAN network, and I need to join some Windows clients from the DMZ network. I read the document at https://wiki.samba.org/index.php/OpenLDAP_as_proxy_to_AD#Authentication_against_AD_through_openLDAP_proxy and it tells about an OpenLDAP proxy to authenticate some external services through it, but I need to join some Windows clients so I think I
2015 Oct 08
4
Samba AD PDC , LDAP and Single-Sign-On
On Oct 8 2015 09:32 Rowlan Penny wrote: > It might help if you were to explain just what you require from single-sign-on ? Well, perhaps I'm mistaken, but is this not the #1 reason to install Samba4? >From reading this list over the past couple of months it does not seem that Authenticating users on Windows workstations is the main thing people do. But, is not the ability to
2015 Oct 08
2
Samba AD PDC , LDAP and Single-Sign-On
On Thu, 08 Oct 2015 21:52 Rowland Penny wrote: > What you cannot do is use GPO's like windows does, everything else is > possible, you just need to setup the clients correctly. Excellent! I've been messing around with GPOs on Windows AD domains for years, more extensively this past year with Samba4 AD/DC and I absolutely hate them. In my opinion they are yet another attempt by
2016 Dec 19
4
Dynamic DNS and bind_dlz
I'm trying to troubleshoot why our workstations have stopped dynamically registering their ip addresses in our AD using bind_dlz setup. It worked for a couple of months and now does not. I realized I have a basic question about how it is supposed to work. Do the workstations (after getting a dynamic address from the dhcpd server) contact the AD DC directly with the information? Or does dhcpd
2008 May 06
1
Users SID problem
Hi. I realized that I have a problem with the users SID. Thy are different between the SID of the domain. Let's see the output of these commands: server:/home/utenti/user# net getlocalsid SID for domain SERVER is: S-1-5-21-1375271547-2371556575-3111006354 server:/home/utenti/user# pdbedit -Lv test Unix username: test NT username: Account Flags: [U ] User SID:
2015 Oct 06
3
gpo failure
Am 06.10.2015 um 21:26 schrieb mourik jan c heupink: > I have checked all our policy directories on sysvol, and I have a > "Registery.pol" only in some "/Machine" directories, and none in "/User" > or "/Group Policy". Do you have any policy in the User tree in the GPME in that GPO? If you never defined one, then the file is missing. Try e. g.
2016 Mar 18
2
Permission denied on GPT.ini (Event ID 1058)
Hi, Yes using rsync followed by a samba-tool ntacl sysvolreset Regards Le 18/03/2016 18:29, lingpanda101 at gmail.com a écrit : > Are you currently replicating the sysvol folder between DC's? > > On 3/18/2016 1:23 PM, Sébastien Le Ray wrote: >> Hi list, >> >> Having a multi-DC Samba 4.1.17 (Debian) setup, we use Computer GPOs. >> >> Machines randomly