Re: Disable "Allow logon to terminal server"

From: Jason Cook (JasonCook_at_discussions.microsoft.com)
Date: 10/20/04

  • Next message: Max: "Load Balancing Issuing CAs"
    Date: Wed, 20 Oct 2004 07:27:04 -0700
    
    

    Steve,

    Thanks for the response. Let me add a little more background which should
    further explain my issue. I need to disable the permission, "Allow logon to
    terminal server," for over 2000 administrative service accounts located on
    800 servers and due to some archaic applications I can not always remove the
    security permission, "logon locally". Manually disabling this property per
    account is not an option I can realistically implement.

    Also, the member server and domain are all Windows 2000 so I do not have the
    TS luxuries provided by Windows 2003 GPOs.

    My gut instinct is that there is likely a way to set this account property
    via a script but I’ve exhausted several searching trying to find it. Any
    additional thoughts would be appreciated…

    Thanks for the response. Let me add a little additional background which
    should further explain my issue. I need to disable the permission, "Allow
    logon to terminal server," for over 2000 accounts located on 700 servers but
    in some instance I can not remove the security permission, "logon locally".

    "Steven L Umbach" wrote:

    > You could remote in via TS to manage those accounts or use security policy
    > to manage the user right for "logon locally" which a user will need to
    > access a TS in W2K. In Windows 2003 that has been changed to a separate user
    > right called "allow logon through Terminal Services". That can be configured
    > through Local Security Policy or you can put the computer in an
    > Organizational Unit with it's own GPO with the logon locally configured to
    > your needs. User rights are accessible through computer
    > configuration/Windows settings/security settings/local policies/user rights.
    > That will not directly configure the user's local account but they can not
    > logon without the logon locally user right. -- Steve
    >
    >
    > "Jason Cook" <JasonCook@discussions.microsoft.com> wrote in message
    > news:1518C02B-BBCA-4C9C-B5AE-1E35C9B4FA99@microsoft.com...
    > > Is there a way to remotely manage (script, GPO, etc) the local account
    > > property, "Allow logon to terminal server" for local accounts on Windows
    > > 2000
    > > servers? The domain is also Windows 2000.
    >
    >
    >


  • Next message: Max: "Load Balancing Issuing CAs"

    Relevant Pages

    • Re: Please help refresh my memory on AD DC
      ... When I boot my Laptop I reach the Logon screeen for XP Laptop and here ... admin account to be able to Login so I can control it from the DC. ... A domain user can by default logon to any domain computer, except Domain controllers. ... A Server has websites already hosted on it in a Workgroup and now I ...
      (microsoft.public.windows.server.active_directory)
    • Re: Please help refresh my memory on AD DC
      ... When I boot my Laptop I reach the Logon screeen for XP Laptop and here I am ... administrator account. ... account to be able to Login so I can control it from the DC. ... A Server has websites already hosted on it in a Workgroup and now I join it ...
      (microsoft.public.windows.server.active_directory)
    • Re: Please help refresh my memory on AD DC
      ... "Meinolf Weber" wrote: ... They however cannot logon directly to the physical DC machine. ... NOT an admin account to be able to Login so I can control it from ... A Server has websites already hosted on it in a Workgroup and now ...
      (microsoft.public.windows.server.active_directory)
    • Re: Please help refresh my memory on AD DC
      ... they just get the result of that what the domain administrator ... They however cannot logon directly to the physical DC machine. ... administrator account. ... A Server has websites already hosted on it in a Workgroup and now I ...
      (microsoft.public.windows.server.active_directory)
    • Re: Please help refresh my memory on AD DC
      ... The users will not see anything of that basically, they just get the result of that what the domain administrator or equivalent configures there. ... They however cannot logon directly to the physical DC machine. ... administrator account. ... A Server has websites already hosted on it in a Workgroup and now I ...
      (microsoft.public.windows.server.active_directory)