?
Solved

Default Domian Group Policy Objects

Posted on 2006-11-09
10
Medium Priority
?
243 Views
Last Modified: 2010-04-11
Hi

I have question from a MS 290 paper that im not clear on


You have a network that runs all win20003 computers.

Three of the servers are Terminal Servers

The company hires 20 temporary staff, and you create an account for each one.

You need to prevent the temp staff from logging onto the Terminal servers.


The answer says. On the Terminal services profile tab for the user account, disable the option to log onto a terminal server.

I understand that. But I do not get why the following will not work

"Modify the Default Domain Group Policy Object (GPO). You should configure a computer level policy to prevent the temporary staff from connecting to the terminal servers"

Why would that not work......If it says modify the policy to prevent the temp staff from getting access, surely that is what you wanted


Thanks
0
Comment
Question by:LFC1980
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 3
10 Comments
 
LVL 85

Expert Comment

by:oBdA
ID: 17908096
Now, which policy exactly would you configure how to achive this result?
There just aren't policies for everything, and there's no computer policy to prevent a group from users logging on to a terminal server.
0
 

Author Comment

by:LFC1980
ID: 17910497
Ah ok.

Cheers mate
0
 

Author Comment

by:LFC1980
ID: 17910543
....sorry. Was just about to make a note of what you said, but in the practise paper it says the only reason the that would not work is, because it will affect all users.

Is the paper printed wrong? Or is there just NO possible way what so ever to prevent access to a terminal server via policy?
0
Bringing Advanced Authentication to the SMB Market

WatchGuard announces the acquisition of advanced authentication provider, Datablink, with one mission – to bring secure authentication to SMB, mid-market, and distributed enterprises with a cloud-based solution, ideal for resale via their established channel & MSSP community.

 
LVL 85

Expert Comment

by:oBdA
ID: 17912797
You can disable remote connections completely through a computer policy, but not for a group of users. Check the policies in Computer Configuration\Administrative Templates\Windows Components\Terminal Services.
In those questions, just because something sounds reasonable and doable does not mean it can actually be done that way.
0
 
LVL 18

Expert Comment

by:PowerIT
ID: 17913390
You can implement a group policy for a group of users by setting the security for 'Apply Group Policy' on the GPO to just the group of users you want.
Of course, this only works if those users are in a OU where the GPO is applied to.
The setting you are looking for is: /Computer Configuration/Administrative Templates/Windows Components/Terminal Services/Allow Users To Connect Remotely using Terminal Services. Set it to Disbaled.

Also by modifying the Default Domain GPO this indeed applies to ALL users. That's why it is the default. GPO are inherited by default, so the Default Domain GPO is the highest level inhertied by all OU's under it. You should create a seperate GPO, you don't want to change the security on the Default Domain GPO.

J.

0
 
LVL 85

Accepted Solution

by:
oBdA earned 252 total points
ID: 17913447
Again: This is a *computer* policy; it can *not* be restricted to a group of *users*.
0
 
LVL 18

Expert Comment

by:PowerIT
ID: 17913900
oBda, I'm restricting access to terminal services using user groups for more then 5 years.
But *not* like I mentioned above. Don't know what happened. Must be because we are Friday.
I'm very very sorry about that :-(

OK, the correct way is through 'Terminal Services Configuration' (on the terminal server itself).
Then open Connections/RDP-TCP.
You'll find a tab 'Permissions' where you can enable and disable user access per user of group.

J.
0
 

Author Comment

by:LFC1980
ID: 17947111
So who is right?
0
 
LVL 18

Assisted Solution

by:PowerIT
PowerIT earned 252 total points
ID: 17947664
Both. I'll explain:
My first statement was wrong, my last is correct.
Which also means that it can not be done using a GPO, only through Terminal Services Configuration combined with a group.
That makes oBda also right ;-)

J.
0
 

Author Comment

by:LFC1980
ID: 17948185
Ah right

Cheers guys
0

Featured Post

Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
If you're a modern-day technology professional, you may be wondering if certifications are really necessary. They are. Here's why.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
This video Micro Tutorial shows how to password-protect PDF files with free software. Many software products can do this, such as Adobe Acrobat (but not Adobe Reader), Nuance PaperPort, and Nuance Power PDF, but they are not free products. This vide…
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question