I have a domain with 2 W2K domain controllers and all of my client PCs are XP pro. My main domain controller has DNS installed on it because that is necessary for AD. (I don’t know enough about DNS as you’ll see). My DNS server is also my DHCP server. My DNS server is not a true DNS because it does not resolve internet names just local names. In my DHCP package I have configured WINS, default gateway, and IP address. I do not send out a DNS server address. This is how we limit internet access. We have a couple of DNS server addresses provided to us by AT&T. For users who are authorized for Internet access, a IT technician will go to the machine and put the provided DNS server IP addresses which allows them internet access. For example, myW2K DNS server address is 192.168.0.10 but the ones we use to access the internet are say 12.156.25.83 (provided by AT&T). This works fine until the domain password for the user has been changed and he has a static DNS server address that is not theone for his domain controller. It will not let him log on because it kind find the DC. Another example, I tried changing the computer name of a PC on the domain that had a static DNS for internet access and it would not allow me because it could notcontact the DC to verify my password. Once I took out the static DNS I had no problem. How can I resolve this, or is there a better way to limit internet access? Thanks in advance.