How can I restrict access to MMC snap-ins?

A. Its possible to restrict access to MMC snap-ins using the Group Policy settings:

  1. Start Active Directory Users and Computers snap-in (Start - Programs - Administrative Tools - Active Directory Users and Computers)
  2. Right click on the domain or OU with the Group Policy set and select Properties
  3. Select the Group Policies tab
  4. Select the Group Policy you wish to change and click Edit
  5. Move to User Configuration\Administrative Templates\Windows Components\Microsoft Management Console
  6. Double click 'Restrict Users to the explicitly permitted list of snap-ins'
  7. Set to Enabled or Disabled.
  8. You can then move to "Restricted/Permitted snap-ins" and enable or disable specific snap-ins

If "Restrict Users to the explicitly permitted list of snap-ins" is set to Disabled or Not Configured then the snap-ins are available unless they are explicitly set to "Disabled" under the "Restricted/Permitted snap-ins" folder.

If the "Restrict Users to the explicitly permitted list of snap-ins" is set to Enabled then no snap-ins are available unless the snap-in is explicitly set to "Enabled".


Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish