prevent legacy operating systems to be added to the domain
hi,<o:p></o:p>
i'm running ad domain windows server 2008 r2 domain , forest function level. domain present in different geographies around globe , notice unsupported operating systems added domain local support teams.
can avoid activity using gpo? goal allow supported systems like, windows 2008, windows 2012, windows 7...
<o:p></o:p>
thanks in advance!<o:p></o:p>
fa<o:p></o:p>
> can avoid activity using gpo? goal allow only
> supported systems like, windows 2008, windows 2012, windows 7...
partially...
you can prevent users adding computers domain:
https://technet.microsoft.com/en-us/library/cc780195(v=ws.10).aspx
you can quarantine new computers in lockdown ou:
https://technet.microsoft.com/de-de/library/cc770619(v=ws.10).aspx
you can not allow os versions , forbid others.
a funny approach maybe work: disable ntlm (enforce kerberos)
and enforce kerberos aes encryption. xp cannot handle :)
Windows Server > Group Policy
Comments
Post a Comment