How to stop users logging onto DC

Posted on 2008-11-10
Medium Priority
Last Modified: 2012-05-05
Is it possible to stop users logging onto the domain controller?
Please do not mention 'Deny log-on locally' I'm talkiing about users who accidently might put in their user name and password into RDC. Let's say I've just been on their machine using RDC. The next time they use RDC to connect to a remote server, they just hit connect, understandably, and do not notice the address field now points to our DC rather than the remote machine.
On the domain controller, 'Deny local log-on' only applies to users attempting  to physically log-on the server; I think.
I just do not want accounts created on the domain controller except mine and admin.
Is this possible?
Is there a GPO setting that can stop this?
Question by:jasonbournecia
  • 2
LVL 27

Accepted Solution

Jason Watkins earned 500 total points
ID: 22923135

You can go into the GPO for the server (DC GPO) and look for the "Allow Log in through Terminal Services"  Add the folks that should have access, all others will not have the ability to do so.  Standard user accounts should not be able to log onto a DC anyway.


Expert Comment

by:Leon Teale
ID: 22923148
isnt there a setting on the DC itsself to only allow admins to log on?
LVL 27

Expert Comment

by:Jason Watkins
ID: 22923227
Active directory should not allow anyone other than a domain admin, server admin, account operator, etc... To log in.

Author Closing Comment

ID: 31515095
Thanks Firebar,
Had a look at the setting, and it is not configured, therefore admin only.
What I don't understand is why under Documentss and settings on the server, the DC, was one of my users!!!!
Got her to try again and she is locked out.

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Loops Section Overview
Look below the covers at a subform control , and the form that is inside it. Explore properties and see how easy it is to aggregate, get statistics, and synchronize results for your data. A Microsoft Access subform is used to show relevant calcul…

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question