Solved

Can a GOP that allows to connect remotely be link to users or need to link to computer

Posted on 2016-08-01
2
52 Views
Last Modified: 2016-08-01
This is how I enabled for users to connect remotely to their computers in the domain

1.      Created a Security Group named RDC
2.      Right-click the new Group and select properties. at Members tab Add the Names or Groups you wish to allow connecting remotely.
4.      Create a GPO. Edit.
5.      Computer Configuration - Policies - Windows Settings - Security Settings - Restricted Groups
6.      Right-click the Restricted Groups folder and click Add Group, enter the name of the Security Group just created.
7.      Right-click the Group, Properties.
8.      Next to the This Group is member of: Add Remote Desktop Users
9.      Navigate to: Computer Configuration - Policies - Administrative Templates - Windows Components - Remote Desktop Services - Remote Desktop Session Host - Connections. Set: Allow users to connect remotely by using Remote Desktop Services.
10.      Network Level Authentication Computer Configuration - Policies - Administrative Templates - Windows Components - Remote Desktop Services - Remote Desktop Session Host - Security. Set require user authentication for remote connections by using Network Level Authentication Enable.
11.      Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile\ Edit: Windows Firewall: Allow Inbound Remote Desktop exceptions: Enable.
12.      Browse to the OU for your computers you want to allow remote desktop connection and link the policy.

Question: does this policy need to  be linked to a OU that have in it the computers I want to allow access remotely or can I place the new created security group in a new OU and link the GOP to it [meaning it will be linked to users not to computers]?
0
Comment
Question by:Abraham Deutsch
2 Comments
 
LVL 39

Accepted Solution

by:
Adam Brown earned 500 total points
ID: 41737666
The GPO settings you have outlined has to be linked to an OU with computer objects in it to apply.

GPOs will also never apply to security groups, so if you create an OU and put a security group in there, the GPO won't apply to the users in that group. You would need to link it to an OU with all the users in it, then change the security of the GPO so only the security group can apply it.
0
 
LVL 2

Author Closing Comment

by:Abraham Deutsch
ID: 41737693
Thank you
0

Featured Post

ScreenConnect 6.0 Free Trial

Discover new time-saving features in one game-changing release, ScreenConnect 6.0, based on partner feedback. New features include a redesigned UI, app configurations and chat acknowledgement to improve customer engagement!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

At the beginning of the year, the IT world was taken hostage by the shareholders of LogMeIn. Their free product, which had been free for ten years, all of the sudden became a "pay" product. Now, I am the first person who will say that software maker…
Synchronize a new Active Directory domain with an existing Office 365 tenant
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question