Solved

Can a GOP that allows to connect remotely be link to users or need to link to computer

Posted on 2016-08-01
2
46 Views
Last Modified: 2016-08-01
This is how I enabled for users to connect remotely to their computers in the domain

1.      Created a Security Group named RDC
2.      Right-click the new Group and select properties. at Members tab Add the Names or Groups you wish to allow connecting remotely.
4.      Create a GPO. Edit.
5.      Computer Configuration - Policies - Windows Settings - Security Settings - Restricted Groups
6.      Right-click the Restricted Groups folder and click Add Group, enter the name of the Security Group just created.
7.      Right-click the Group, Properties.
8.      Next to the This Group is member of: Add Remote Desktop Users
9.      Navigate to: Computer Configuration - Policies - Administrative Templates - Windows Components - Remote Desktop Services - Remote Desktop Session Host - Connections. Set: Allow users to connect remotely by using Remote Desktop Services.
10.      Network Level Authentication Computer Configuration - Policies - Administrative Templates - Windows Components - Remote Desktop Services - Remote Desktop Session Host - Security. Set require user authentication for remote connections by using Network Level Authentication Enable.
11.      Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile\ Edit: Windows Firewall: Allow Inbound Remote Desktop exceptions: Enable.
12.      Browse to the OU for your computers you want to allow remote desktop connection and link the policy.

Question: does this policy need to  be linked to a OU that have in it the computers I want to allow access remotely or can I place the new created security group in a new OU and link the GOP to it [meaning it will be linked to users not to computers]?
0
Comment
Question by:Abraham Deutsch
2 Comments
 
LVL 38

Accepted Solution

by:
Adam Brown earned 500 total points
Comment Utility
The GPO settings you have outlined has to be linked to an OU with computer objects in it to apply.

GPOs will also never apply to security groups, so if you create an OU and put a security group in there, the GPO won't apply to the users in that group. You would need to link it to an OU with all the users in it, then change the security of the GPO so only the security group can apply it.
0
 
LVL 1

Author Closing Comment

by:Abraham Deutsch
Comment Utility
Thank you
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
Security measures require Windows be logged in using Standard User login (not Administrator).  Yet, sometimes an application has to be run “As Administrator” from a Standard User login.  This paper describes how to create a shortcut icon to launch a…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now