Create email only user account (prevent login to domain computers)

There are many ways to prevent Active Directory users from logging on to certain computers. For large and more complicated scenarios it's best to use Group Policy.

But if I need to create a few "email only" user accounts I normally do following:

Enable Group Policy (GPO) logging

To enable GPO startup / shutdown / log-on / log-off logging:

  • Open registry editor (regedit.exe) and navigate to:
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics
    Create key "Diagnostics" if it does not exist.
  • Create new DWORD Value called GPSvcDebugLevel and set value (HEX) to 0x30002
  • Restart the PC

Windows 7


Subscribe to receive occasional updates on new posts.
Your email will not be used for any other purpose and you can unsubscribe at any time.
Please wait