cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
873
Views
0
Helpful
2
Replies

restrict non-domain computers

Does anyone know if it is possible to restrict access based on domain membership or an AD Group?

The purpose is to restrict non-domain computers even if the client has a legitimate domain credential to use for authentication.

2 Replies 2

jason.spangler
Level 1
Level 1

I believe you could put these PCs into a different subnet and create a policy based on the subnet.

I think so anyway.

-
Jason

jowolfer
Level 1
Level 1

That is correct. The only way to restrict these computers would be to make a rule (above your auth group policies), that states the specific IPs / subnets are granted certain / no access.

As long as the rule is above all your auth rules, it will trigger first and take precedence. Be sure to disable WBRS for this rule as well, since there is a potential for +6 sites to be allowed.