Solved

SBS2011 Standard and Remote Desktop Services Group Policy

Posted on 2011-03-17
2
918 Views
Last Modified: 2013-11-21
Hi,
I have SBS2011 Std installed on one server and on another server I have Windows 2008 R2 with Remote Desktop Services enabled.  Office 2010 and Adobe Reader are the only apps installed so far.  So far everything seems to be working but I have a couple of issues with GPO settings.

One of the things I have noticed is that the RDS Users can still access the Powershell.  As these will be troubled youth using the system I would really like to lock these down but I cannot find a setting to do this.

The second issue is that I would like to ask a big favour, if possible.  Does anyone have a set of GPO settings documented that would provide a basis for me to base my GPO on.  I presume it would be for SBS2008 and Terminal Services but it would at least give me a head start.  I have found that it is VERY different to the 2003 Terminal Servers I have set up in the past and I have got masses of settings enabled so that it now looks a mess.
0
Comment
Question by:jimcrint
2 Comments
 
LVL 74

Accepted Solution

by:
Glen Knight earned 250 total points
ID: 35163783
Probably the easiest way to do this is to use a software restriction policy and block powershell.exe, see here for further details: http://technet.microsoft.com/en-us/library/bb457006.aspx

You can also block access to certain control panel applets under the User Configuration\Administrative Templates\Control Panel section of the group policies.

There really isn't any ready built GPO's as everyones will be different depending on their particular needs.
0
 
LVL 1

Author Closing Comment

by:jimcrint
ID: 35169476
Thanks for your reply.  I realise each situation is unique (re: GPO) but was really only looking for a base template similar to one that was produced for SBS2003 and TS by the girls at smallbiznet (I think).

However, your answer is probably the closest I will get to what I want so full points to you.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

OfficeMate Freezes on login or does not load after login credentials are input.
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now