Solved

Disable Remote Logon for Local administrator with group policy

Posted on 2013-06-25
5
1,675 Views
Last Modified: 2013-06-26
I'm trying to disable remote logon for just the local administrator account on every workstation thats on our domain.  I would like to use group policy to do so.  IS there a way to accomplish this?

Thanks,
0
Comment
Question by:IslandIT
  • 3
5 Comments
 
LVL 80

Expert Comment

by:David Johnson, CD, MVP
ID: 39277358
remove the administrator local account from the remote desktop users local group
0
 

Author Comment

by:IslandIT
ID: 39277844
can you do that through group policy?  When I try and add administrator it asks for the local administrator of the DC.
0
 
LVL 27

Accepted Solution

by:
Steve earned 500 total points
ID: 39278269
when adding local users to GPO you have to avoid using AD to select the user so it forces the local account to be used.

Just type 'administrator' directly in the box instead of using the browse/AD search box
0
 
LVL 80

Expert Comment

by:David Johnson, CD, MVP
ID: 39278332
Start | Run | Gpedit.msc if editing the local policy or chose the appropriate policy and edit it.

2. Computer Configuration | Windows Settings | Security Settings | Local Policies | User Rights Assignment.
3. Find and double click "Deny logon through Remote Desktop Services"
4. Add the user and / or the group that you would like to dny access.
5. Click ok.
6. Either run gpupdate /force /target:computer or wait for the next policy refresh for this setting to take effect.

http://support.microsoft.com/kb/2258492
0
 
LVL 80

Expert Comment

by:David Johnson, CD, MVP
ID: 39278394
Group PolicyAfter Policy
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The related questions "How do I recover the passwords for my Q-See DVR" and "How can I reset my Q-See DVR to eliminate a password" are seen several times a week.  Here we discuss the grim reality of the situation.
Most MSPs worth their salt are already offering cybersecurity to their customers. But cybersecurity as a service is wide encompassing and can mean many things.  So where are MSPs falling in this spectrum?
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question