Re: Disallowing console login on w2k3



I don't know of anyway where you can explicitly disallow a user to use the
console yet be able to logon to the box remotely. The only way I know is
don't allow remote access, via the rdp configuration.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

<styles.q@xxxxxxxxx> wrote in message
news:1179711707.696424.64330@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Is it possible to disallow console login for certain users/groups?

By console login in mean using RD like so:

mstsc /v:box1 -console

The scenario is that I would like for only one user on the box to be
allowed to login to the console (session 0). This is because the box
is running an application that unfortunately cannot be run as a
service, thus we need to preserve the console login and do not want
any other user assuming session 0.

I know you can disable kicking off an admin logged in to session 0 in
gpedit, but i would like to go one step further and explicity deny the
right to all users except for one.

Is it possible?

Thanks
JS



.



Relevant Pages

  • Re: WTSQuerySessionInformation
    ... Session zero has stopped being `the console session` starting from Vista. ...
    (microsoft.public.win32.programmer.kernel)
  • RE: emote console, WlxQueryConsoleSwitchCredentials, and WlxGetConsole
    ... logout from TS Session, you have to do same on workstation. ... Remote console logon. ... The weird thing is that the local consol goes in "log off" state - ...
    (microsoft.public.platformsdk.security)
  • Re: Updating status - REMOTE INTERACTIVE LOGON vs. INTERACTIVE
    ... There is no built-in way to have XP automatically update the user's security token because of a session state change. ... What specific resources/objects are you attempting to secure based on console versus RDP? ... you connect via Remote Desktop. ... LOGON. ...
    (microsoft.public.windows.terminal_services)
  • Re: microsoft RDP client control
    ... The locally logged in user is typically on the "console" session. ... always log in to the console, whether locally or remote. ... On Windows Server 2003 the behavior is different. ...
    (microsoft.public.dotnet.languages.vb.controls)
  • Re: Local and remote connection in parallell
    ... Win2K3 server allows two remote sessions and one console ... to the console session, it will lock the desktop... ...
    (microsoft.public.windowsxp.work_remotely)