[Samba] [OT?] 'negative' GPOs for local user?!

Marco Gaiarin gaio at sv.lnf.it
Mon Mar 5 13:37:03 UTC 2018

Mandi! Rowland Penny via samba
  In chel di` si favelave...

> You probably could, but all 'Authenticated Users' will be domain
> members and as such will also be members of the 'Domain Users' group,
> so why bother.

No. But wait... AHA! Sorry to the list, sorry Rowland: i've two
policies, one that set profile quota (user-based), and one that set
profile path (computer based).
Effectively the computer-based policy apply also to local users, so
local users get a ''roaming'' profile set (that clearly does not work)
but no quota, as expected.

So, simply a question remain: there's some way to set a computer policy
based on users?

Probably the answer is 'no', and this lead as a consequences that
profiles it is better to be defined in user data and not in policies...

> I feel that you haven't  explained your set up very well, especially
> your 'local users'.

Oh, a local user, for example:

	net user ospite ospite /fullname:"Utente Ospite" /comment:"Utente ospite sicuro" /passwordchg:no /expires:never
	wmic USERACCOUNT WHERE "Name=ospite" SET PasswordExpires=FALSE

('ospite' mean 'guest' in italian).

dott. Marco Gaiarin				        GNUPG Key ID: 240A3D66
  Associazione ``La Nostra Famiglia''          http://www.lanostrafamiglia.it/
  Polo FVG   -   Via della Bontà, 7 - 33078   -   San Vito al Tagliamento (PN)
  marco.gaiarin(at)lanostrafamiglia.it   t +39-0434-842711   f +39-0434-842797

	(cf 00307430132, categoria ONLUS oppure RICERCA SANITARIA)

More information about the samba mailing list