Solved

RDP sessions need to be locked down to certain users

Posted on 2014-07-23
5
128 Views
Last Modified: 2014-08-02
So I inherited a terminal server and thought it was locked down. I saw the policy and it was only showing the groups that I want security filtering applied to. The issue is that it only applies to them and no one else. I want to block all other access to that terminal server unless you part of those groups. How do I block everyone else?
0
Comment
Question by:lgalan01
  • 4
5 Comments
 

Author Comment

by:lgalan01
ID: 40215001
I have added the groups to the local group "Remote Desktop Users" but still users who aren't in those groups can connect to the server. They also are able to access the server without any of the GPO restrictions. I hope that clarifies it more for you guys.
0
 
LVL 5

Expert Comment

by:Sean Jackson
ID: 40215016
I believe you can set this as a Group Policy in Active Directory.  Your Domain Admins likely have access.  Check those.
0
 

Author Comment

by:lgalan01
ID: 40215253
So far I have add authenticated users to the "security filtering" and now Administrator has all GPO restrictions when they log into the server. I need to know how do I block everyone except helpdesk, administrator and two security groups.
0
 

Accepted Solution

by:
lgalan01 earned 0 total points
ID: 40224844
Found the answer here:
http://www.it-book.co.uk/766/create-a-%E2%80%9Clockdown%E2%80%9D-gpo-for-a-terminal-or-citrix-server-3

Section:
Optional � I also like to set a “deny” permission to make sure that this GPO doesn’t apply to administrators (i.e. so you have full access to the server).
0
 

Author Closing Comment

by:lgalan01
ID: 40235958
It allowed my to assign a group to that the GPO doesn't apply to.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question