RE: Terminal Services - Domain Controller - Normal User

From: Bates, Chris (Chris.Bates_at_nwdc.net)
Date: 02/25/05

  • Next message: Roger McLaren: "Re: Terminal Services - Domain Controller - Normal User"
    Date: Fri, 25 Feb 2005 13:11:37 -0800
    To: "Michael Scheidell" <scheidell@secnap.net>, "Robert Abela" <robert@gfi.com>, focus-ms@securityfocus.com
    
    

    Yes, just add them to a domain local group, then grant that local group
    the rights to log into the DC via RDP via DC Group Policy, and set the
    permissions on the RDP Adapter in TS Admin console to grant login to the
    domain local group above.
     

    --------------------------------------------------------
    Chris Bates
    ACS; Enterprise Services

    -----Original Message-----
    From: Michael Scheidell [mailto:scheidell@secnap.net]
    Sent: Friday, February 25, 2005 12:28 PM
    To: Robert Abela; focus-ms@securityfocus.com
    Subject: RE: Terminal Services - Domain Controller - Normal User

    Yes, promote them to domain administrators.

     

    > -----Original Message-----
    > From: Robert Abela [mailto:robert@gfi.com]
    > Sent: Friday, February 25, 2005 3:07 AM
    > To: focus-ms@securityfocus.com
    > Subject: Terminal Services - Domain Controller - Normal User
    >
    > HI,
    >
    > To log on via terminal Services (administration mode) on a Domain
    > controller one needs to be an Administrator of the domain (like a
    > member of the enterprise administrators, or domain administrators
    > etc), since a domain controller doesn't have its own groups.
    >
    > Are there any particular permissions or way to set it up to give a
    > normal user logon access (via terminal services, administration mode)
    > to the domain controller?
    >
    > Kind regards,
    >
    > Robert Abela - GFI Software Ltd. - www.gfi.com Messaging, Content
    > Security & Network Security Software
    > GFI: MailSecurity - FAXmaker - MailEssentials - LANguard
    >
    >
    >
    >
    > This mail was checked for viruses by GFI MailSecurity.
    > GFI also develops anti-spam software (GFI MailEssentials), a fax
    > server (GFI FAXmaker), and network security and management software
    > (GFI LANguard) - www.gfi.com
    >
    >
    > --------------------------------------------------------------
    > -------------
    > --------------------------------------------------------------
    > -------------
    >
    >
    >

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ---
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Roger McLaren: "Re: Terminal Services - Domain Controller - Normal User"

    Relevant Pages

    • RE: Permissions
      ... administrative permissions in each domain (Domainb.local ... Create a local group on the member server in the ... >Symptom 1 often occurs when the domain administrators ...
      (microsoft.public.win2000.security)
    • Re: Settle a Administrators dispute
      ... in the Administrators built in group and when I logged on with the user, I couldn't create/modify/delete users or modify distribution groups. ... Administrators Local Group on the DC but not in the Domain Admins ... Or with a restricted group in group policy. ... giving domain users administrative rights on their workstations is a very bad idea but then it sounds like they're already domain admins so I don't suppose it makes much difference now. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Settle a Administrators dispute
      ... the Administrators Local Group ON THE DOMAIN CONTROLLER. ... Administrators Local Group on the DC but not in the Domain Admins ... Or with a restricted group in group policy. ...
      (microsoft.public.windows.server.active_directory)
    • Re: localgroup administrators
      ... I took the original post at face value of "set a group ... policy to remove domain users and only add domain admins to local group ... administrators on workstations", which translates in my brain as a full ... admins to local group administrators on workstations. ...
      (microsoft.public.windows.group_policy)
    • Re: Add users to local admin via login script
      ... net localgroup administrators interactive /add ... used to add the user to a local group, ... so a Startup script can add users to local ... The suggested solution is to use a Startup script to add a domain group to ...
      (microsoft.public.windows.server.active_directory)

  • Quantcast