- Home
- Information Security
- Limiting Interactive Log On in Windows 2000
Limiting Interactive Log On in Windows 2000
This document describes how to set the local security policy for logging on locally to a Windows 2000 machine.When setting this policy it limits who can log on interactively to the machine and complies with the School of Medicine Workstation Best Practices.
From the Start menu select Settings, Control Panel.
Double click on the Administrative Tools icon.

The Administrative tools window will appear.

Double click on the Local Security Policy icon. The Local Security Settings window will appear.

Under the Tree tab double click the Local Policies folder

Click on the user rights assignment folder.

Scroll down until the Log on Locally policy appears.

Double click on the Log on Locally policy. The Local Security Policy Setting window will appear.

Uncheck the Backup Operators, Power Users and Users boxes and then click the Add. button. The select Users or Groups will appear.
Note: Make sure the Administrators box stays checked.

Enter in YALE\Netid. The netid should be of a client who should have access to log on to this machine. If you need to add multiple clients separate each with a semicolon.

Click OK. The window will return to the Local Security Policy Setting window.

Once all the users have been added, click OK.
Close the Local Security Settings window for the policy to take effect.
Now the Local Security Setting is now set for the Log on local policy.