Click here to get back home

Default Domain Users group

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Default Domain Users group Pete 03-24-2008
Posted by Pete on March 24, 2008, 1:59 pm
Please log in for more thread options
Hello,
Would it be safe for me to remove Domain users group from servers local
users group? I understand the purporse of this group on the workstations side
but not sure why it would be in the server that has joined Domain.

If no local security restrictions are in place then any domain users will be
able to log into the server via console.


Thank you in advance for your suggestions and reading this post!!

Posted by Anthony [MVP] on March 24, 2008, 2:15 pm
Please log in for more thread options
You could remove Domain Users from local Users, but that would presume that
you were trying to allow local accounts but prevent domain accounts, and it
does not sound as though that is what you had in mind.
If you want to control who can log on locally, the place to do it is in the
User Rights Assignment policy: either the local security policy or an
applied Group Policy. If you want to prevent people apart from
administrators from logging on locally, in User Rights Assignment just
remove the Users group from the right to Log on Locally.
Hope that helps,
Anthony,
http://www.airdesk.co.uk




> Hello,
> Would it be safe for me to remove Domain users group from servers local
> users group? I understand the purporse of this group on the workstations
> side
> but not sure why it would be in the server that has joined Domain.
>
> If no local security restrictions are in place then any domain users will
> be
> able to log into the server via console.
>
>
> Thank you in advance for your suggestions and reading this post!!



Posted by Roger Abell [MVP] on March 24, 2008, 7:01 pm
Please log in for more thread options
It is normal in some shops to remove Domain Users and replace this
with domain group(s) that should have access, whether this is done
on member servers or client machines.

Roger

> Hello,
> Would it be safe for me to remove Domain users group from servers local
> users group? I understand the purporse of this group on the workstations
> side
> but not sure why it would be in the server that has joined Domain.
>
> If no local security restrictions are in place then any domain users will
> be
> able to log into the server via console.
>
>
> Thank you in advance for your suggestions and reading this post!!



Similar ThreadsPosted
Adding another domain users to your local domain admin group December 28, 2005, 12:19 pm
removing user from domain users group doesn't help June 23, 2006, 4:15 pm
Can I delete 'Athenticated Users' group form local 'Users' group January 29, 2008, 11:52 am
possible to change Default Share Permission for Group "Everyone"? June 6, 2005, 1:26 pm
Reset Group Policy back to out of the box default August 28, 2006, 11:19 am
Can login domain be set to a default? August 31, 2005, 2:09 am
secpol on DC vs. Default Domain Policy? November 30, 2006, 6:12 pm
Default Domain Controllers Policy scope May 15, 2006, 11:26 am
Default domain controllers policy not applied to my server (2k3 sbs) January 3, 2006, 8:32 am
Performance Monitor Users Group June 17, 2005, 8:09 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap