How can I restrict access to MMC snap-ins?

John Savill

June 3, 2000

1 Min Read
ITPro Today logo in a gray background | ITPro Today

A. Its possible to restrict access to MMC snap-ins using the Group Policy settings:

  1. Start Active Directory Users and Computers snap-in (Start - Programs - Administrative Tools - Active Directory Users and Computers)

  2. Right click on the domain or OU with the Group Policy set and select Properties

  3. Select the Group Policies tab

  4. Select the Group Policy you wish to change and click Edit

  5. Move to User ConfigurationAdministrative TemplatesWindows ComponentsMicrosoft Management Console

  6. Double click 'Restrict Users to the explicitly permitted list of snap-ins'

  7. Set to Enabled or Disabled.

  8. You can then move to "Restricted/Permitted snap-ins" and enable or disable specific snap-ins

If "Restrict Users to the explicitly permitted list of snap-ins" isset to Disabled or Not Configured then the snap-ins are available unless theyare explicitly set to "Disabled" under the "Restricted/Permittedsnap-ins" folder.

If the "Restrict Users to the explicitly permitted list ofsnap-ins" is set to Enabled then no snap-ins are available unless thesnap-in is explicitly set to "Enabled".

About the Author

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like