WinSecWiki > Security Settings > Local Policies > User Rights > User Rights In-Depth > Deny network access
Deny access to this computer from the network
AKA: SeDenyNetworkLogonRight, Deny access to this computer from the network
Default assignment: None
This is the opposite of Access this computer from the network and any user with both rights will be denied network logons. See discussion of logon rights.
Assigning this right on domain controllers, can break many Active Directory programs such as Active Directory Users and Computers because even if you are logged on locally to a domain controller, all Active Directory programs use a network logon to access Active Directory.
Back to top