?
Solved

Can a GOP that allows to connect remotely be link to users or need to link to computer

Posted on 2016-08-01
2
Medium Priority
?
63 Views
Last Modified: 2016-08-01
This is how I enabled for users to connect remotely to their computers in the domain

1.      Created a Security Group named RDC
2.      Right-click the new Group and select properties. at Members tab Add the Names or Groups you wish to allow connecting remotely.
4.      Create a GPO. Edit.
5.      Computer Configuration - Policies - Windows Settings - Security Settings - Restricted Groups
6.      Right-click the Restricted Groups folder and click Add Group, enter the name of the Security Group just created.
7.      Right-click the Group, Properties.
8.      Next to the This Group is member of: Add Remote Desktop Users
9.      Navigate to: Computer Configuration - Policies - Administrative Templates - Windows Components - Remote Desktop Services - Remote Desktop Session Host - Connections. Set: Allow users to connect remotely by using Remote Desktop Services.
10.      Network Level Authentication Computer Configuration - Policies - Administrative Templates - Windows Components - Remote Desktop Services - Remote Desktop Session Host - Security. Set require user authentication for remote connections by using Network Level Authentication Enable.
11.      Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile\ Edit: Windows Firewall: Allow Inbound Remote Desktop exceptions: Enable.
12.      Browse to the OU for your computers you want to allow remote desktop connection and link the policy.

Question: does this policy need to  be linked to a OU that have in it the computers I want to allow access remotely or can I place the new created security group in a new OU and link the GOP to it [meaning it will be linked to users not to computers]?
0
Comment
Question by:Abraham Deutsch
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 42

Accepted Solution

by:
Adam Brown earned 2000 total points
ID: 41737666
The GPO settings you have outlined has to be linked to an OU with computer objects in it to apply.

GPOs will also never apply to security groups, so if you create an OU and put a security group in there, the GPO won't apply to the users in that group. You would need to link it to an OU with all the users in it, then change the security of the GPO so only the security group can apply it.
0
 
LVL 3

Author Closing Comment

by:Abraham Deutsch
ID: 41737693
Thank you
0

Featured Post

Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Suggested Courses

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question