AD DC. How to prevent users from logging into computers in the domain and use the account only to login?

I want to authorize all users of corporate mail (Not Exchange) on their uchetku in AD. With the users of the office everything is clear, but there are also remote branches that are not domain members, and workers without a workplace in the office. How do I properly provide authorization for these remote users, but not allow them to log on to domain computers?
July 9th 19 at 12:52
1 answer
July 9th 19 at 12:54
Solution
ADUC->user Properties->Account->Log on->Only on specified computers, the list is left empty
Yes, at the moment do. Thanks for the reply. - Jensen.Rosenbaum commented on July 9th 19 at 12:57
Can be automated via PoSH, so do not fool each time - Erling_Conroy commented on July 9th 19 at 13:00
It would be nice, but is DC on SAMBA. After evaluating all the disadvantages of such DC will eventually move to a Windows DC. - Jensen.Rosenbaum commented on July 9th 19 at 13:03
Checked - I have not saved an empty list resets back to "all computers". - antonette_Bro commented on July 9th 19 at 13:06
And it is true. But perhaps the same effect will, if you deny entry at the time. - Jensen.Rosenbaum commented on July 9th 19 at 13:09
well, create uchetku fake PC and select it. - Erling_Conroy commented on July 9th 19 at 13:12

Find more questions by tags Active DirectoryLDAP