Managing Active Directory…now a child’s play!!

As a matter of fact, active directory acts as a centralized platform for system administrators and help desk personnel to not only save but also alter the information related to users, computers, printers and more. Put in simple words, there are numerous things that you can do with the help of the active directory.

Mentioned below is one such activity that you can perform using the active directory.

Let’s consider a real life scenario wherein you want to restrict the logon hours that a user may log on to Windows Server 2003 domain.

You can set a user account’s logon hours by the below mentioned two ways:

Using the Active Directory service users and computers Snap-in, you can edit the user account properties.

Using the net user command, you can edit the user account properties.

Method 1: Use the Active Directory Users and Computers Snap-in
1.Click Start -> Administrative Tools -> Active Directory Users and Computers
2.In the console tree, click the container that contains the desired user account.
3.Right click the user account and then click Properties.
4.Click the Account tab.
5.Click Logon Hours.
6.To select all available times, click All.
7.Click Logon Denied.
8.Select the time and then click Logon Permitted.
Currently selected logon times displays. For instance, Tuesday to Saturday from 9 A.M. to 7 P.M.
9.Click the Ok button.
10.In the User Account Properties dialog box, click the Ok button.
11.Quit the Active Directory Users and Computers Snap-in.

Method 2: Use the Net User Command Line Statement
1.Click Start -> Run.
2.In the Open box, type cmd, and then click the Ok button.
3.Type net user username /time:logon_times
where username is the user account name
logon_times are the days and times that you want to allow access to the domain
4.Press the Enter key.

By performing any of the above mentioned methods, you can set the logon hours of a user account.

