Remote Desktop Services - Non-Best Practices Setup

I've got a very strange setup that I'm working on. I've got a doctor's office running a practice management software on Server 2008 R2, which is also running Remote Desktop Services for remote users. This server is a member server. The domain controller is running Server 2003 R2. I know this is not a best practices situation, but due to software manufacturer restrictions, we are unable to promote the Server 2008 R2 machine to a DC or PDC. The Server 2003 R2 machine is also running Terminal Services. I would like to set up both servers to disable the shutdown button when users are logged on remotely. What would be the best way to go about doing this?
horizontechgroupAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

jonyeltonCommented:
You can use group policy to disable this option,

User Configuration\Administrative Templates\Start Menu & Taskbar
"Disable and remove the Shut Down command"
0
Venugopal NCommented:
User config -> admin templates -> start menu and taskbar -> remove and prevent access to the shutdown, restart, sleep and hibernate comands = enabled

Can you the plolicy above to block the user from rebooting the server, when they login to the server through COnsole.

If you need to block the shutdown in terminal server mode then need to enable the Loopback Processing on the Terminal server.For more information refer the below link...

http://support.microsoft.com/kb/260370
http://www.petenetlive.com/KB/Article/0000499.htm
0
Cláudio RodriguesFounder and CEOCommented:
Make sure your policy does NOT apply to administrators otherwise you may prevent admins from shutting down the box.
For the 2008 R2 box I would put it on its on OU and apply a policy in Loopback replace mode that would apply to two groups, to be created:
RDS_Servers: Add the 2008 R2 to this group and any other future RDS boxes.
RDS_Users: Add all users that need TS/RDS access. Do not add any admin here.
The policy would apply to these two groups only, at the OU level.
Everything is explained in great detail on the guide I wrote, "Terminal Services: from A to Z". Even though it was written for 2003, all the foundation applies to 2008 R2 as well. Available for download at no cost at http://www.wtslabs.com.

Cheers.

Cláudio Rodrigues
Microsoft MVP - RDS
Citrix CTP
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Protecting & Securing Your Critical Data

Considering 93 percent of companies file for bankruptcy within 12 months of a disaster that blocked access to their data for 10 days or more, planning for the worst is just smart business. Learn how Acronis Backup integrates security at every stage

horizontechgroupAuthor Commented:
What about removing "Administrative Tools" from the start menu?
0
Cláudio RodriguesFounder and CEOCommented:
On 2008 that is controlled by Group Policy Preferences.

Cláudio Rodrigues
Microsoft MVP - RDS
Citrix CTP
0
horizontechgroupAuthor Commented:
So, since the 2008 server is only a member server, is that in the local policy?
0
Cláudio RodriguesFounder and CEOCommented:
The problem is not he is a member server. You can manage GPPs from any 2008 DC but as you are 2003 this may not be possible so a local policy will do it I assume.

Cláudio Rodrigues
Microsoft MVP - RDS
Citrix CTP
0
horizontechgroupAuthor Commented:
Thanks for all the help, Cláudio!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.