Limit RDP to desktop for single user in AD

Posted on 2011-05-09
Last Modified: 2012-05-11
WE are migrating from NT4 to AD. At the moment domain users are in the local administrators group. Due to the timescales for migration I have decided to use a restricted group and allow only intercative user to be in the admin group. So when the user logs off they will not be able to have admin rights on the PC from a remote location. We have serveral developers that work in a test area, they will need to RDP to their own PC and check email, docs etc. How can I only allow that user to RDP to his/her own desktop using GPO? Is it possible?

Question by:Sarah_Smith
    LVL 37

    Accepted Solution

    It's possible, but probably preferrable to just set the groups manually on the computers, because you would need a different GPO for each computer. The Remote Desktop Users group that is on each local computer is used to control which users have Remote Desktop Access to the computer. Adding the user to that group will give them access. Having only that user in the group will set that up.
    LVL 6

    Assisted Solution

    You could just set the permission on their AD account to only allow login to 'their desktop machine' and whatever one they are connecting from.  Also, add them to the RD group in AD.  I assume the clients and machines are in AD.
    LVL 1

    Author Comment

    @acbrown2010 : Yes I will try that, for some reason I was getting confused thinking the restricted group would overwrite the members of the RDP group. However if the RDP group is not specified in the GPO then it wont touch it. :) Ill give it a whirl...


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Do you have users whose passwords are expiring and they are constantly calling you?  Well I sure did and needed a way to put an end to this.  We have a lot of remote users which would not be notified that their passwords were expiring since they wer…
    This is a little timesaver I have been using for setting up Microsoft Small Business Server (SBS) in the simplest possible way. It may not be appropriate for every customer. However, when you get a situation where the person who owns the server is i…
    Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
    With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

    759 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    11 Experts available now in Live!

    Get 1:1 Help Now