Re: Need help locking down a server



Thanks all for the input. For now, we ended up setting some allow/deny local
logon and remote desktop access to our IT staff. We also have changed the
admin password. Not as complicated as I thought....

"Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> wrote in message
news:eYMCDh8HHHA.1248@xxxxxxxxxxxxxxxxxxxxxxx
Hi Chris

You would probably be well-informed by checking into
http://www.microsoft.com/technet/security/guidance/default.mspx
particularly in the "by product" section the two guides you will
locate under Exchange Server and under Windows 2003 Server

While I agree, it is admirable to limit excess administrative
access, I am scratching my head at the net result of your 3
proposed actions.

One controls local logon by use of the User Rights settings
that govern the machine. One may list groups and/or accounts
in the grants of logon rights (or deny of same).

"Chris Hall" <someone@xxxxxxxxxxxxx> wrote in message
news:e7gSEe5HHHA.3952@xxxxxxxxxxxxxxxxxxxxxxx
Greetings,

I'm looking into options to secure our mail server (Exchange 2003 on
Windows
2003). We have an IT staff of 5 people, which includes our dept mgr, all
of
which have access to the administrator password and whose accounts are
members of the Domain Admins group. What I propose to do is:

1. Change Admin password, allowing only one person access.
2. Disable Remote Desktop
3. Deny Logon Locally.

The only thing I can't seem to figure out is how to deny all users
except
administrator.

If anyone has any suggestions, I'd appreciate it!






.



Relevant Pages

  • Re: The local policy of this system does not permit you to logon interactively
    ... system does not permit you to logon interactively". ... administrator, domain user, local administrator, local user, or other type? ... How to reset security settings back to the defaults ... Remote desktop connection "The local policy of this system does not permit ...
    (microsoft.public.windows.server.sbs)
  • Re: The local policy of this system does not permit you to logon interactively
    ... system does not permit you to logon interactively". ... administrator, domain user, local administrator, local user, or other type? ... How to reset security settings back to the defaults ... Remote desktop connection "The local policy of this system does not permit ...
    (microsoft.public.windows.server.sbs)
  • Re: The local policy of this system does not permit you to logon interactively
    ... system does not permit you to logon interactively". ... administrator, domain user, local administrator, local user, or other type? ... How to reset security settings back to the defaults ... Remote desktop connection "The local policy of this system does not permit ...
    (microsoft.public.windows.server.sbs)
  • Re: Cant log on locally to XP after RDP session
    ... To control the ability to logon to your Terminal Servers via Remote Desktop, use membership of each server's local Remote Desktop Users group, except for DCs where you would use a combination of the Domain Local RDU group and RDP-Tcp listener object permissions. ... The "Deny this user permissions to log on to any Terminal Server" check box in the user account properties is *not* used in most cases. ...
    (microsoft.public.windowsxp.work_remotely)
  • RE: Remote Desktop not working after SP1
    ... "The local policy does not permit you to logon interactively" error message ... Remote Desktop Users ... Use the ISAinfo utility to collect the ISA configuration information: ...
    (microsoft.public.windows.server.sbs)