Solved

Remove Shutdown option for specific servers

Posted on 2008-06-24
14
9,808 Views
Last Modified: 2008-07-24
I want the Shut Down option to be removed from all servers. I have the servers in their own OU and a policy that restricts only Domain Admins to be able to shut down. But the only way to remove this option is via User Configuration setting. When this setting is applied to any users, those users are also restricted from seeing the Shut Down option on ALL copmuters, not just the servers.
0
Comment
Question by:itadmins590
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
  • 2
  • +1
14 Comments
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 21856814
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 21856880
One more this that might be a better solution. Set up local policies on these servers. Go to computer config -> Windows settings -> security -> user right assignment -> shut down the system.
0
 

Author Comment

by:itadmins590
ID: 21857102
This only setup permissions to who is allowed to shut down. As I am allowed, I could accidentally hit the Shut Down options sense it still shows. I want it to be hidden from me only on servers.

Thanks
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:itadmins590
ID: 21857186
This only hides the Disconnect option from Terminal sessions. I log on as a Domain Admin via RDC, and the Shut Down option is visible, just want to hide this option.

Thanks
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 21857532
You can hide this option in the local policy User Configuration - Administrative Templates - Start Menus and TAskbar - Remove and prevent access to the shutdown command {enabled}
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21857608
In re: dariusg's suggestion - be aware that if your environment has any domain-based Group Policy Objects configured that define these settings, the domain-based GPOs will overwrite any local policies that you have configured on each server.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 21857628
For got to mention that.
0
 

Author Comment

by:itadmins590
ID: 21857759
I saw that option, but wanted to do it via Domain GP as to limit the amount of work. We have over 50 servers and it would take a while to modify each local policy. If I edit this option in Domain GP, it will apply to every server and pc which we don't want.

Thanks
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 21858043
I don't know of another way except through the local policy which won't effect any of  the users if they aren't logged into the terminal server.

http://nicolask.wordpress.com/2008/02/17/copy-local-policy-settings-between-servers/
0
 
LVL 5

Accepted Solution

by:
minvis earned 125 total points
ID: 21873264
Use loopback processing (Computer configuration > administrative templates > system > group policy > loopback processing) to apply a user setting to a computer.

http://support.microsoft.com/kb/231287/en-us
0
 

Author Comment

by:itadmins590
ID: 21887501
<P>Sounds like the loopback option is the way to go, although it is not working. Perhaps I'm not configuring it correctly. The servers are in a OU by themselves, I created a GPO with the Loopback seeting, set it to merge. Then in the same GPO set a user settings to hide the Shutdown.</P><P>Is this correct?</P>
0
 
LVL 5

Expert Comment

by:minvis
ID: 21891582
Completely correct. this should work. can you make screendumps?
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
Suggested Courses

626 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question