You have multiple options:
* Use ADUC and bring up Properties dialog of the user and in "Terminal Services Profile"-tab, check the "Deny this user permissions to log on to any Terminal Server"
* Remove the user from "Remote Desktop Users" or other group that has been granted the right "Allow log on through Terminal Services"
* Configure user rights assignment to set the "Deny log on through Terminal Services" to deny a group of users
Both allow and deny log on rights are located in "Computer Configuration\Windows Settings\Local Policies\User Rights Assignment" and be configured either in local policy or a GPO linked to the OU with the computer objects that shall be affected.
Main Topics
Browse All Topics





by: Oliver-PPosted on 2009-07-25 at 07:11:07ID: 24941730
Hello,
I don't get it... If you want to exclude a group of users from using RDP, you can exclude them from the Remote Desktop Users group.
But I'm sure you're facing a different problem, so could you explain a bit more please.