- Home
- Information Security
- Limiting Interactive Log On in Windows XP
Limiting Interactive Log On in Windows XP
This document describes how to set the local security policy for logging on locally to a Windows XP machine. When setting this policy it limits who can log on interactively to the machine and complies with the School of Medicine Workstation Best Practices
From the Start menu select Control Panel. The Control Panel windows will appear.
Double click on the Administrative Tools icon.

The Administrative tools window will open.

Double click on the Local Security Policy icon. The Local Security Settings window will appear.

Double click the Local Policies folder

Click on the User Rights Assignment folder.

Scroll down until the Log on Locally policy appears.

Double click on the policy. The Log on locally Setting window will appear.

Highlight and remove the Backup Operators, Guest, Power Users and Users groups. Note: Make sure the Administrators group is not removed.

Next click the Add User or Group. button. The Select Users or Groups window will appear.

Enter in YALE\Netid. The netid should be of a client who should have access to log on to this machine. If you need to add multiple clients separate each with a semicolon.

Click OK.

Once all the users have been added, click OK.
Close the Local Security Settings window.
Now the Local Security Setting is now set for the Log on local policy.