الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

سؤال: تحديد مجموعة مستخدمين لكل جهاز على الدومين

بدأه abdokelaly في 4 ديسمبر 2009 · 8 رد · 2,980 مشاهدة · في Active directory
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

السلام عليكم

اخوانى الكرام

ارجو مساعدتى فى سؤال بخصوص صلاحيات المستخدمين على اجهزة الدومين

أى جهاز نضيفه على الدومين تلقائيا يضاف اليه فى ال users group جروب أسمه Domain users

الكلام ده معناه أن انا شغال فى شركه فيها 1000 جهاز وحوالى 1500 مستخدم

كل مستخدم يستطيع الدخول الى أى جهاز كمبيوتر مجود فى الشبكه بما ان المستخدم عضو فى مجموعة Domain users

كيف يمكن تحديد مجموعه معينه يمكنها الدخول الى جهاز كمبيوتر معين

يعنى من الأخر كده

عاوز اخلى

Marketting_Users (login to)-> Marketting-PC

Sales_Users (login to)-> Sales-PC

Accounting_Users (login to)-> Accounting-PC

بس طبعا الأجهزه مش تلاته بس

ياريت الطريقه تكون من ال Group policy عشان الدنيا تبقى جميله بس

شكرا

#2

you can achive a sort of than using a mix of user's attribute and group policy.

you can right click on the user and define login to which restricts to which computers the user can login.

also you can use GPO and define logon localy policy which sets who can login to a group of computers locally, this applies to group of computers and sets the permissions to groups or users.

in your case I will recommend the GPO solution

Mahmoud Magdy

MVP - Exchange Server. MCITP (Windows Server 2008, Exhcange Server 2010,/2007),CCNP, MCTS(OCS 2007 R2, SCCM 2007)

Tech Lead

Ingazat Information Technology

Follow me on twitter: http://www.twitter.com/_busbar

my blog: http://autodiscover.wordpress.com

Link with me on linkedin: http://www.linkedin.com/profile?viewProfile=&key=71027694

or on experts-exchange.com: http://www.experts-exchange.com/M_1426100.html

#3

شكرا خى الكريم

انا عاملها فعلا من خلال Restricted Groups

لكن انا عندى اجهزه كتيره جدا الكلام ده معناه ان حاجه من الاتنين :

1- كل جهاز يكون فى Organizetional Unit لوحده وأحط لكل هجاز GPO خاص بيه.

أو

2-كل الاجهزه هتكون فى OU واحده هحط لكل جهاز GPO خاصه بيها فيها الجروب المسموح بيه فى ال Restricted Groups

وطبعا هاستخدم الصلاحيات بحيث اخلى كل GPO مكن قراءته لأجهزه معينه.

أنا عندى فكره بس مش عارف اطبقها.

بص !!

انا عندى مثلا اجهزه اسمها : Sales - Store - Accounting - Dispatching

عملت مجموعات اسمها Sales_LocalLogin - Store_LocalLogin - Accounting_LocalLogin - Dispatching_LocalLogin

هاجى على ال Group policy وأعمل فى ال Restricted Groups التالى : Computername%_LocalLogin%

بمعنى بدال ما اخلى اسم الجروب ثابت وده هيخلينى اعمل جروبز كتير

أربط الجروب بمتغير يحمل أسم الجهاز لكن الفكره مش شغاله لأن ال group policy لا تقوم بقراءة ال Environment Variables

جارى البحث عن فكره اخرى

شكرا

#4

الموضوع يحتاج كما ذكرت لإعادة هيكلية ال OU Structuring اتستطيع تطبيق ال GPO بشكل سليم.

It's hard to stay in such ridiculous situation

#5

keep in mind that this will not be done using restricted group but it will be done using logon locally policy in the GPO settings

Mahmoud Magdy

MVP - Exchange Server. MCITP (Windows Server 2008, Exhcange Server 2010,/2007),CCNP, MCTS(OCS 2007 R2, SCCM 2007)

Tech Lead

Ingazat Information Technology

Follow me on twitter: http://www.twitter.com/_busbar

my blog: http://autodiscover.wordpress.com

Link with me on linkedin: http://www.linkedin.com/profile?viewProfile=&key=71027694

or on experts-exchange.com: http://www.experts-exchange.com/M_1426100.html

#6

creat some groups for your departments .. sales , store , HR ... etc

do the same by creating OUs .. each department has its OU

creat GPOs .. each OU has its GPO and apply the following

creat two scripts and run them with a startup of all your domain computers

the first will use to remove the domain goup DOMAIN USERS from the local group Users that found in SAM database

the second script will use to add the specific domain group ( e.g. sales , HR .. etc ) to the local group USERS

Regards ,,

System Administrator

#7

thank you brothers

Mr Busbar

I tried to do it using Login Locally Option

but it also not working

I Also should create 100 GPO for 100 PCs

do you know why ?

when i say Allow Login Locally for Group_Name and apply it to the OU .. All PCs will be Affected with This GPO

شكرا اخى Yassean

الفكره التى طرحتا جيده لكن غير امنه بالدرجه الكافيه

ماذا يحدث اذا حدث خطأ ما فى تطبيق ال policy التى تقوم بتشغيل الباتش الذى يعدل فى ال groups ؟ وهذا وارد جدا فى الشبكات

هذا ببساطه يعنى ان جميع ال Domain Users لديهم صلاحيه بالدخول على الجهاز كما انه من غير الأمن الوثوق فى اعدادات الحمايه اذا كانت محدده من خارج الدومين كنرولر

الحل الأمن الوحيد المتاح هو ان انشئ لكل جهاز كمبيوتر GPO خاصه به وأقوم بأعدادها لتنظيم المجموعات المسموح بها لكل جهاز من خلال Restricted Groups وذلك لمنع أى تعديل غير مشروع

فى ال User groups الخاصه بكل جهاز وأيضا بأستخدام Allow Login Locally للمذيد من الحمايه

شكرا

#8

then something is wrong in your method of applying it not in the policy

Mahmoud Magdy

MVP - Exchange Server. MCITP (Windows Server 2008, Exhcange Server 2010,/2007),CCNP, MCTS(OCS 2007 R2, SCCM 2007)

Tech Lead

Ingazat Information Technology

Follow me on twitter: http://www.twitter.com/_busbar

my blog: http://autodiscover.wordpress.com

Link with me on linkedin: http://www.linkedin.com/profile?viewProfile=&key=71027694

or on experts-exchange.com: http://www.experts-exchange.com/M_1426100.html

#9

انا عامل الفكرة دي بس بشكل تاني

مقسم الاجهزة مجموعات agents - sales -....

ولكل مستخدم في login بيدخل على اجهزة مجموعته فقط

ومن باب الاحتياط تختار view--> advanced option

لما تختار الكمبيوتر هتلاقي باب جديد secuirty

ممكن تعمل dany للكل ماعدا المجموعة بتاعته فقط

مواضيع مشابهة