Logon Using Terminal Services GPO



Hi All,
I've searching high and low for an answer but it doesn't look like
anyone has asked this question before. The company I work for has 5
domain controllers (all in separate locations - Aus, UK, India etc).
The company's main IT Dept (who I work for) admins all these servers,
though recently we have employed some systems admin contractors to
look after the AD servers in India.

The server is in a rack with no monitor attached so the only way for
these guys to log in is via RDP/Terminal Services. I have added their
user account in "Domain Controller Security Policy" -> "User Rights
Assignment" -> "Allow log on through Terminal Services".

So now they can logon remotely and administer the server (check event
logs, create users etc). I have also given them the right to shut down
the server, as from time to time they may need to bounce the server
for hardware upgrades etc.

Though I do not want them having RDP access or shutdown other servers
within the domain. Unfortunately the GPOs that I've edited give these
users those permissions throughout all domain controllers.

Is there a way to specify which domain controllers I want these users
to be able to RDP & shutdown.

.



Relevant Pages

  • Re: GP to force Daily Restart
    ... The Security System could not establish a secured connection with the server ldap/DC01.corp.com/corp.com@xxxxxxxxx No authentication protocol was available. ... The network path was not found. ... domain controllers log these events every five minutes. ... every computer on the network must use DNS servers that can resolve SRV ...
    (microsoft.public.windows.server.sbs)
  • Re: Net logon error event id:3096
    ... Verifying that the local machine yblrtgswip1, ... Connecting to directory service on server yblrtgswip1. ... No record of File Replication System, ... interval between domain controllers. ...
    (microsoft.public.win2000.active_directory)
  • Re: Installing Windows 2003 DC in a Windows 2000 Evironment-- Need Hel
    ... How to Upgrade Windows 2000 Domain Controllers to Windows Server 2003 ... Initial synchronization requirements for Windows 2000 Server and Windows ... ensure that you have designed a DNS and Active ...
    (microsoft.public.windows.server.active_directory)
  • RE: Provide feedback to DC promotion/replacement
    ... I did look at the live production domain controllers and noticed both have ... A global catalog server is a domain controller that, ... If the server holding ... the infrastructure master is also a global catalog it won't ever see any ...
    (microsoft.public.windows.server.active_directory)
  • RE: Provide feedback to DC promotion/replacement
    ... I did look at the live production domain controllers and noticed both have ... Also, for your comment on part 1, can I force a replicate by right-clicking ... A global catalog server is a domain controller that, ... If the server holding ...
    (microsoft.public.windows.server.active_directory)