I have a small network (250 users) of users who assign their own domain and workgroup names to their equipment. This is in violation of our local security practice so I have been trying to determine if I can restrict the domain and workgroup names allowed on the network.
We have a series of servers/services that all users connect to (like print, collaboration, Internet etc.) and most are hosted within a single Active Directory Forest. (User must authenticate to AD before proceeding to the service).
In Active Directory, you can restrict access to various components of the Network Connections GUI. Look at the available settings in User ConfigurationAdministrative TemplatesNetworkNetwork Connections, as well as User ConfigurationAdministrative TemplatesControl Panel. Group Policy Objects can be configured so that they apply to any user on a machine, even those with administrative access.
Dig deeper on Microsoft Active Directory Tools and Troubleshooting
Related Q&A from Laura E. Hunter
Active Directory expert Laura E. Hunter offers some advice for changing the IP addresses of domain controllers.continue reading
An admin needs to grant user access rights for those needing to traverse directory trees. Our server management expert explains how to use Group ...continue reading
A Windows administrator moving from Windows Server 2003 to Windows Server 2003 R2 wants to perform a restore of a previous server to a new one ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.