The most appropriate method is to use aGroup Policy Object (GPO) with time-of-day restrictions (A). This is a native capability in Windows environments that allows administrators to controlwhen users are allowed to log into domain-joined systems.
This aligns withDomain 3.1: Given a scenario, apply identity and access management (IAM) concepts, especially under“Access controls (e.g., time-based restrictions, GPOs, least privilege).”
[Reference: CompTIA Security+ SY0-701 Objectives, Domain 3.1 – “Access controls: Time-based restrictions, GPO.”, , , , , , ]
Submit