How to stop users logging onto DC

Posted on 2008-11-10
Last Modified: 2012-05-05
Is it possible to stop users logging onto the domain controller?
Please do not mention 'Deny log-on locally' I'm talkiing about users who accidently might put in their user name and password into RDC. Let's say I've just been on their machine using RDC. The next time they use RDC to connect to a remote server, they just hit connect, understandably, and do not notice the address field now points to our DC rather than the remote machine.
On the domain controller, 'Deny local log-on' only applies to users attempting  to physically log-on the server; I think.
I just do not want accounts created on the domain controller except mine and admin.
Is this possible?
Is there a GPO setting that can stop this?
Question by:jasonbournecia
    LVL 27

    Accepted Solution


    You can go into the GPO for the server (DC GPO) and look for the "Allow Log in through Terminal Services"  Add the folks that should have access, all others will not have the ability to do so.  Standard user accounts should not be able to log onto a DC anyway.

    LVL 6

    Expert Comment

    by:Leon Teale
    isnt there a setting on the DC itsself to only allow admins to log on?
    LVL 27

    Expert Comment

    by:Jason Watkins
    Active directory should not allow anyone other than a domain admin, server admin, account operator, etc... To log in.

    Author Closing Comment

    Thanks Firebar,
    Had a look at the setting, and it is not configured, therefore admin only.
    What I don't understand is why under Documentss and settings on the server, the DC, was one of my users!!!!
    Got her to try again and she is locked out.

    Featured Post

    Better Security Awareness With Threat Intelligence

    See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

    Join & Write a Comment

    Organizations create, modify, and maintain huge amounts of data to help their businesses earn money and generally function.  Typically every network user within an organization has a bit of disk space to store in process items and personal files.   …
    On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
    Need more eyes on your posted question? Go ahead and follow the quick steps in this video to learn how to Request Attention to your question. *Log into your Experts Exchange account *Find the question you want to Request Attention for *Go to the e…
    Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…

    732 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now