Is there a way for a Windows 2000 Server domain controller to restrict logins to only domain users on computers that reside in the domain. For example, domain user Joe should be able to login to the domain on domain machine JOESCOMP, but not on JOESLAP, which is a laptop not in the domain. I looked for ways to set this up using the Security snap-in, but couldn’t find anything. I also checked in the Active Directory with no luck. Any help would be appreciated.