Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Logon Script Amateur 1

Status
Not open for further replies.

ricolame

IS-IT--Management
Nov 9, 2005
82
CN
Hi guys,

I just started putitng my hands on using Logon Script in my domain.

Would need assistance - I have created a script.bat file.

How I went into inserting my script:

In my AD, my default domain(top of the directory). Right click->properties-> i got into my default domain policy edit mode.

After which, i went under User Configuration ->Windows Settings-> Script->Logon-> And insert in my file script.bat

I read from the Net that i would also need to place the similar file in Netlogon shared folder. I placed the similar file in the following directory too

%SystemRoot%\sysvol\sysvol\<domain DNS name>\scripts

Since i have applied the script to default domain policy, it should work on all terminals in my domain right? However, my testing on a terminal didnt work at all. The script was not running.

Could someone enlighten me ? I've been doing this for the day and itz really nerve wrecking... Any help is greatly appreciated. Thanks in advanced!
 
On why IPs were fixed, internet access restriction was done on the IPs. Say for certain range of IP, port 80 is allowed, and the rest are all blocked for 80

While you have found one solution to block users access to the Internet it wont work if a user were to sign onto another PC (unless you are also restricting access to PCs).

I'd suggest that instead of your current approach you simply use GPO to set a fake proxy value for your "Non Internet" users. That way whenever they log on the fake proxy will be set for them (and not other users of the same PC). Because it will be forced down via GPO your users will not be able to override it unless you are giving them Local Admin Access to the PC.

I hope you find this post helpful.

Regards,

Mark
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top