Domain admins certain users limit

One member of domain admins I want to deny access to rdp and local console login to AD server or certain server. How do I do that?
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Carlos ElguetaIT ManagerCommented:
Domain admins are meant to administer your domain; therefore, you will have to remove him/her from the domain admins group...
I partly agree with Carlos's comment above, but to answer your question - you can modify your local security policy of the server in question, and add the user to the "Deny log on through Remote Desktop Services", as shown in the screenshot.

Deny Log on through Remote Desktop Services
You can also deny log on locally (the setting above the highlighted one) if you believe him or her to have physical access or access via KVM - or if it is a virtual server, then access via a console

Denied permissions will override allowed permissions.

I just want to point out that disallowing the user DOES NOT prevent them from creating another active directory user - making that new user domain admin - and then logging in as that user to gain access to said server.  They are a domain admin after all, and can do this.  If you believe this user to be untrustworthy, you should reconsider their domain admin privileges.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.