Solved

Disable Remote Logon for Local administrator with group policy

Posted on 2013-06-25
5
1,630 Views
Last Modified: 2013-06-26
I'm trying to disable remote logon for just the local administrator account on every workstation thats on our domain.  I would like to use group policy to do so.  IS there a way to accomplish this?

Thanks,
0
Comment
Question by:IslandIT
  • 3
5 Comments
 
LVL 79

Expert Comment

by:David Johnson, CD, MVP
ID: 39277358
remove the administrator local account from the remote desktop users local group
0
 

Author Comment

by:IslandIT
ID: 39277844
can you do that through group policy?  When I try and add administrator it asks for the local administrator of the DC.
0
 
LVL 27

Accepted Solution

by:
Steve earned 500 total points
ID: 39278269
when adding local users to GPO you have to avoid using AD to select the user so it forces the local account to be used.

Just type 'administrator' directly in the box instead of using the browse/AD search box
0
 
LVL 79

Expert Comment

by:David Johnson, CD, MVP
ID: 39278332
Start | Run | Gpedit.msc if editing the local policy or chose the appropriate policy and edit it.

2. Computer Configuration | Windows Settings | Security Settings | Local Policies | User Rights Assignment.
3. Find and double click "Deny logon through Remote Desktop Services"
4. Add the user and / or the group that you would like to dny access.
5. Click ok.
6. Either run gpupdate /force /target:computer or wait for the next policy refresh for this setting to take effect.

http://support.microsoft.com/kb/2258492
0
 
LVL 79

Expert Comment

by:David Johnson, CD, MVP
ID: 39278394
Group PolicyAfter Policy
0

Featured Post

Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Site-To-site VPN Natting inbound traffic? 9 71
Risks of using Camtasia Studio 9 53
Access 2016 5 54
User Level Security 6 38
The 21st century solution to antiquated pagers.
As technology users and professionals, we’re always learning. Our universal interest in advancing our knowledge of the trade is unmatched by most industries. It’s a curiosity that makes sense, given the climate of change. Within that, there lies a…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question