An administrator is creating user accounts for a new vendor contract. The contract states that the users can work only during certain times. Which of the following should the administrator implement to comply with this requirement?
A.
Timeout policies by GPO user objects
B.
Alerts on authentication attempts outside of SLA requirements
C.
Expirations on the contractors ' accounts
D.
Account login restrictions set to the specified hours
The requirement is that vendor users can work only during certain times , which is enforced by setting logon-hour restrictions on the accounts. Quentin Docter explicitly describes this control under “Setting Time Restrictions,” stating: “Configure user accounts so that logins can occur only during times that the user can be expected to be working,” and explains that in Active Directory you can open the user account and click Logon Hours to configure permitted and denied hours. This directly matches option D.
Option C (account expiration) is useful for contractors, and Docter even notes account expiration is “best used on contractor accounts,” but that controls the end date of access, not daily working hours . Alerts (B) would only notify after the fact, and timeout policies (A) are about inactivity/session controls rather than restricting when logons are allowed. Mike Meyers also lists “login time restrictions” as an account management best practice, reinforcing that restricting logon times is a valid security control.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit