Deny log on locally
Verified with Windows Security Options 25H2 — updated on July 25, 2026
Security policy
This is a Security Options policy (Windows Settings > Security Settings), applied by the security engine — not an Administrative Template (ADMX). In GPMC/gpedit it is configured under Local Policies > Security Options.
Path in the GPO console
Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment Description
This security setting determines which users are prevented from logging on at the computer. This policy setting supersedes the Allow log on locally policy setting if an account is subject to both policies. Important If you apply this security policy to the Everyone group, no one will be able to log on locally. Default: None.
Local security policy
SeDenyInteractiveLogonRight This setting has no registry key. It is stored in the local security database (LSA) and is configured through the Group Policy console or secpol.msc.