Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Stopping one person being able to logonto more than 1 PC at a time

Status
Not open for further replies.

AcornD

IS-IT--Management
May 22, 2002
37
GB
We have a problem of pupils telling friends their password and when they have been locked out for missuse they are login on with their friends username and password sometimes we can have the same pupil loged onto several machines we are trying our best to stop this we have been told once we upgraded to windows 2000 server we would be able to stop this happening

Any ideas or suggestion
 
AcornD - you'd be better posting this in the 2k server forum - forum96.
 
First, I am going to say that you need to nip this right in the bud anyway.....Users SHOULD NOT be sharing usernames and passwords. Your company should have a policy against it, and there should be repercussions for inappropriate use. Namely, the individual that gave out his password should be held responsible, and you can easily trace that. If your company doesn't have that policy, you need to get with senior management and implement it. Make sure all employees are notified of this NEW policy, give them a short grace period, then slap em.

Second, you should tighten your password change parameters for you network. Normally procedure is every 30, 60 or 90 days you have to change your password. If this is not the case, you should make it. Make it even shorter if necessary (I wouldn't recommend much less than 30 days....gets real old real fast reseting passwords for users forgetting).

Finally, depending on you NOS, you should be able to restrict a login to certain machine, one machine, etc. I know for a fact that in at least Novell Netware 5.x and newer, you have options to restrict a user to a particular machine or give them access to any PC, and can restrict their login to only be used one time in the network or as many times as you want. I believe NT had something similar as to the number of concurrent logins, and I am about 95% sure W2K does also...

****************************
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former. (Albert Einstein)

Robert L. Johnson III
MCSA, CNA, MCP, Network+, A+
w: robert.l.johnson.iii@citigroup.com
h: wildmage@tampabay.rr.com
 
Why not limit in GPO....? Makes more sence and is not as time consuming....

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top