Solved

Windows 2008R2 Terminal Services Server - Logoff vs shutdown

Posted on 2014-10-15
3
306 Views
Last Modified: 2014-10-16
This is a two-fold question.   Our Windows 2008R2 Terminal Server was shutdown remotely yesterday.  I need to know how to remove the "shut down" option from the dropdown menu that is adjecent to the <Logoff> button while in a RDP session.  In other words, I believe one my remote users clicked the small down arrow next to the <Log Off> button which displayed a dropdown menu and they selected "Shut Down"...I need to know how to eliminate the "shut down" option from the dropdown menu.

And secondly, is there an easy way either via the logs or some other fashion to determine which user shut down the TS Server?

Thank you in advance for your reply...I appreciate any comments.
0
Comment
Question by:infosys3
3 Comments
 
LVL 13

Assisted Solution

by:akb
akb earned 250 total points
ID: 40383601
By default regular users do not have a Shutdown option in RDP. I suspect the are in the Administrator group where they could do a lot of damage.
I'm not sure about the logs. You should have a look in Event Viewer at the logs immediately prior to the shutdown.
0
 
LVL 7

Accepted Solution

by:
Stampel earned 250 total points
ID: 40383850
In the windows eventviewer you can find this in the log security and stuff.
(Launch it with command "eventvwr" from start menu)
In the system log you will see if the shutdown was regular (by a user) or forced (power issue / hang ..). You will have to look arround the datetime of the reboot.
Looking at the file "pagefile.sys" you can find the datetime of this reboot easily.
0
 

Author Closing Comment

by:infosys3
ID: 40384966
Thank you gentlemen for your timely response.  As it turned out MS automatic security updates which happened at 3:30am required a reboot.  Unknowningly, I immediately took this situation as user issue.  I am splitting the 500 points between the both of you.

akb:  I have checked all user accounts and I have a handle on who in in the administrator group.  Thanks.

Stampel:  After searching diligently in the event viewer I found an event where a restart is required to complete the installation of the updates.

Thank you both again for your help.  I appreciate it.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

INTRODUCTION The purpose of this document is to demonstrate the Installation and configuration, of the HP EVA 4400 SAN Storage. The name , IP and the WWN ID’s used here are not the real ones. ABOUT THE STORAGE For most of you reading this, you …
OfficeMate Freezes on login or does not load after login credentials are input.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

832 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question