[Samba] prevent ldap bind for specific user

lists lists at merit.unu.edu
Tue Dec 3 15:45:40 UTC 2019

Hi Rowland,


On 3-12-2019 16:32, Rowland penny via samba wrote:
> How about using the userAccountControl attribute ?
> Add 2 to it and the account becomes disabled and a disabled account 
> cannot authenticate to AD

But the accounts still needs to be able to logon to certain (a specific 
list of) workstations...

A disabled account account can not logon at all.


More information about the samba mailing list