• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 549
  • Last Modified:

Is it possible to limit RDP sessions without making the server a Terminal Server

Is it possible to limit RDP sessions without making the server a Terminal Server?  Running 2003 standard.  The server has custom software installed on it and the person that did this is long gone.  He gave the users access to the server console with RDP.  I do not think it is possible to limit the admin RDP session without making the server a terminal server, but I thought I would ask.
0
asrvwiz
Asked:
asrvwiz
  • 12
  • 8
  • 3
  • +2
3 Solutions
 
md624Commented:
Login an administrator to the console session. Lock the console session. This will deny access to the console session for other users.

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Q_26409405.html

You must first disable remote logoff of an administrator, though.

http://www.raseley.com/2009/04/21/deny-logoff-of-an-administrator-logged-in-to-the-console-session/
0
 
saastechCommented:
I believe you can do you this. Look at the permission properties window of the RDP.  I have not managed Windows 2003 in awhile but if you can do it in Windows 2008 and Windows 7, i dont see why it may not be there for Windows 2003.

Good Luck.
0
 
c0sCommented:
The maximum is 2 sessions, what you can do is force log off after a specific amount of time for idle connections. this can be done through group policy
0
Cloud Class® Course: Certified Penetration Testing

This CPTE Certified Penetration Testing Engineer course covers everything you need to know about becoming a Certified Penetration Testing Engineer. Career Path: Professional roles include Ethical Hackers, Security Consultants, System Administrators, and Chief Security Officers.

 
asrvwizAuthor Commented:
Not sure if I am confused or I did not explain it correctly.  I want the user to be able to RDP BUT limit them to only what I want them to see.  IE:  launch explorer and only present them with the icons in that folder, without giving them a desktop.
0
 
c0sCommented:
I dont believe windows can do that by default without additional software
0
 
asrvwizAuthor Commented:
I believe you must take the server out of remote admin mode and install the terminal server option in add/remove programs, but I was not 100% certain.
0
 
md624Commented:
If you want remote file access to the server, why not just create a share for users to navigate from the network? Even with Terminal Services installed, you will not be able to tightly control the UI. This would require something like Citrix.
0
 
nappy_dThere are a 1000 ways to skin the technology cat.Commented:
You CAN do it with Citrix but you need to have Active Directory to enforce group policy objects by users and/or groups.
0
 
asrvwizAuthor Commented:
The user needs access to a program on the server, and possibly printers.  I have another terminal server that presents an application to the users and that is all the users have access too.
0
 
c0sCommented:
i am guessing you are ussing some kind of software to accomplish that, try to find out what is the software in use and use the same on your new server
0
 
nappy_dThere are a 1000 ways to skin the technology cat.Commented:
And is that other terminal server part of Active Directory?
0
 
asrvwizAuthor Commented:
Yes the other server is part of AD.
0
 
nappy_dThere are a 1000 ways to skin the technology cat.Commented:
Then my previous comment stands. You require AD to configure this server. Are both servers part of the same company?
0
 
asrvwizAuthor Commented:
Nappy_d,

All I want to accomplish is to allow the user to RDP to the server and have the server present an application.  I am currently doing this on another server.  The other server is in remote admin mode.  I believe I must install terminal services to accomplish this?
0
 
nappy_dThere are a 1000 ways to skin the technology cat.Commented:
I understand what you want to accomplish.  But it is all happens with GPOs and AD.  If you do it on a stand alone terminal server without AD present, you will lock ALL users out with the same forced settings, including the administrator.
0
 
asrvwizAuthor Commented:
OK Nappy_d Where do I start with this?
0
 
asrvwizAuthor Commented:
Nappy_d,

I have decided to put the server into terminal services mode.  The vendor of the software package says it should work in terminal services mode.
0
 
nappy_dThere are a 1000 ways to skin the technology cat.Commented:
Great!  Do you know how to add your Server to the TS licensing server?
0
 
asrvwizAuthor Commented:
Yes, I have another one running.
0
 
nappy_dThere are a 1000 ways to skin the technology cat.Commented:
anything else I can help you with?
0
 
asrvwizAuthor Commented:
Nappy_d,

Yes!!!   I have put the server in TS mode and it works as designed.  When I set an papplication to run it presents just the app, no desktop.  What I need to do is present windows explorer, with a specific folder that I have shortcuts in.  When I try to do this I get a full desktop.
0
 
asrvwizAuthor Commented:
I got it to work with some html, and launching iexplore
0
 
nappy_dThere are a 1000 ways to skin the technology cat.Commented:
Cool. You can also try calling this "explorer.exe <drive>:\path to folder"
0
 
asrvwizAuthor Commented:
Nappy_d

Explorer will not work, because it is the desktop.   As soon as you call explorer you get a desktop.
0
 
asrvwizAuthor Commented:
The user needed to launch multiple applications.  I accomplished this by creating an html file, and launching internet explorer, with hyperlinks to all the applications.  I used GP preferences to deliver shortcuts to the user’s desktops for the file access to the server, thus taking the need for access to windows explorer out of the mix.  I got a break because one of the applications opened the printers.  Not sure how to accomplish that without the vendor doing it, without a desktop.
0
 
nappy_dThere are a 1000 ways to skin the technology cat.Commented:
Take a look at www.2x.com.   This is lower cost competitor to Citrix and appliction presentation.  it also allows for printing.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 12
  • 8
  • 3
  • +2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now