How to use logon scripts to enforce login time restrictions across departments. Limiting when users can log in helps reduce security risks, minimize after-hours attack exposure, and keep access aligned with company policies. While Active Directory has built-in login time controls, PowerShell scripts give you much more flexibility. In this video, we'll show you how to use logon scripts to enforce login time restrictions by department. Before we begin, be sure to subscribe to NinjaOne's IT Video Hub and our YouTube channel for more tech content like this. Step 1: Determine the department and the allowed login window. To get started, you'll need to define login time windows for each department. Open PowerShell as administrator, paste the following code, and press Enter. To detect a user's department from Active Directory, use this script instead. Step 2: Create the logon script logic. After defining the login windows, it's time to build the login script logic. Open PowerShell as administrator again, then enter this code into the prompt and press Enter. Remember, it's best to test the change locally before rolling it out to other endpoints. Step 3: Deploy logon script using Group Policy. Next, you'll deploy the logon script using Group Policy. Open Group Policy. Go to User Configuration, Windows Settings, Scripts , then add the PowerShell script created earlier. Next, make sure the execution policy is set to remote signed under Computer Configuration, Administrative Templates, Windows Components, Windows PowerShell. Set the policy to allow local scripts and remote signed scripts. Step 4: Log enforcement status to the registry. Once the policy is in place, you can use a PowerShell script to record enforcement actions locally. To do this, in PowerShell enter this code into the prompt. Keep in mind that registry logging is useful for local auditing, but centralized logging platforms or SIEM tools provide more secure and scalable reporting. To check what's inside your custom registry key, you can use CMD. Open CMD as administrator. Enter the following command in the prompt. Alternative method: CMD and net user alternatives. This is a built-in Windows and Active Directory option for administrators who want to restrict login times without using scripts. To do this, open CMD. Enter the following code into the prompt. Do note that this approach has some limits. It doesn't offer UI-based enforcement and can't be customized by department without separate OU targeting. Setting login times by department helps enforce organizational policies, reduce after-hours attack exposure, and support compliance requirements. Logon scripts also help reduce unauthorized after-hours access and protect sensitive business data. For more information, check out our official blog post on how to use logon scripts to enforce login time restrictions, linked in the description below.

How to Use Logon Scripts to Enforce Login Time Restrictions Across Departments

Learn how to enforce department-based login time restrictions using PowerShell logon scripts and Group Policy. In this video, we walk through defining login windows, building script logic, deploying via GPO, and logging enforcement actions—plus a quick look at built-in Active Directory alternatives.

Perfect for IT admins looking to improve security, reduce after-hours risk, and stay compliant with access policies.

Read the full blog on How to Use Logon Scripts to Enforce Login Time Restrictions Across Departments

Never miss a NinjaOne video!