Adding Authorization Controlled Domain Groups: Difference between revisions

From Pumping Station One
Skynaya (talk | contribs)
Skynaya (talk | contribs)
 
(3 intermediate revisions by the same user not shown)
Line 22: Line 22:
** For example: Boss Laser Authorized
** For example: Boss Laser Authorized
* Create an Authorizer security group
* Create an Authorizer security group
** For example: Boss Laser Authorizer  
** For example: Boss Laser Authorizer
** NOTE: Now is a good time to add all Authorizer (likely danger committee users) to this group.


=== 2) Django Steps ===
=== 2) Django Steps ===
Line 43: Line 44:
******* (Policy) Allow Log On Locally  
******* (Policy) Allow Log On Locally  
******** (Setting) PS1\Domain Admins, PS1\[Authorizer Security Group], PS1\[Authorized Security Group], BUILTIN\Administrators, BUILTIN\Administrators  
******** (Setting) PS1\Domain Admins, PS1\[Authorizer Security Group], PS1\[Authorized Security Group], BUILTIN\Administrators, BUILTIN\Administrators  
******* Local Policies / Security Options
****** Local Policies / Security Options
******** (Policy) Interactive Logon: Do not require CTRL+ALT+DELETE
******* (Policy) Interactive Logon: Do not require CTRL+ALT+DELETE
*********(Setting) Disabled
********(Setting) Disabled
******* Restricted Groups
****** Restricted Groups
******** (Group) PS1\[Authorizer Group]
******* (Group) PS1\[Authorizer Group]
********* (Member Of) BUILTIN\Administrators
******** (Member Of) BUILTIN\Administrators
** User Configuration
** User Configuration
*** NONE
*** NONE
Line 55: Line 56:


[[File:BossGroupPolicy.png|Example of group polciy]]
[[File:BossGroupPolicy.png|Example of group polciy]]
== Final Notes ==
To finalize the changes, it is recommended you reboot the affected computer, or run "gpupdate /force" from a command prompt.