Re: Restricting RDP to 2k3 DCs to only specific admins and not the entire admin group



You can modify the default DC security policy. There is an option there named "Allow log on through Terminal Services". But why do you need this? As long as they are domain admins they can connect by using other methods (like Dameware or VNC).

Regards,
Andrei Ungureanu
www.itboard.ro

"Roger Abell [MVP]" <mvpnospam@xxxxxxx> a scris în mesaj news:eJHGMzwwIHA.1772@xxxxxxxxxxxxxxxxxxxxxxx
In your administrative tools, on each DC, start the Terminal Services
Configuration and with Connections highlighted on the left, right click
on the RDP-tcp connectoid in the right pane and select properties and
then select the permissions tab and adjust as needed.

"J" <usenet@xxxxxxxxxxxxx> wrote in message news:b289ddfb-01eb-4c3d-bb80-aed851a78fb9@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
The title pretty much sums it up. Is there a way to restrict RDP
access to our 2k3 DCs so that only certain admin accounts can RDP in
and not the entire Administrators group? My Google-fu is failing me
and we haven't found any method that works so far.

Thanks
J


.



Relevant Pages

  • Re: Restricting Domain Admins
    ... > Change the security on the adminSDHolder container so that domain admins ... > Modify Permissions ... >>> Removed Modify permission ... >>> Removed modify owner permission ...
    (microsoft.public.windows.server.security)
  • Re: Restricting Domain Admins
    ... > protect the domain admins group to the level that I require. ... >>> Modify Permissions ... >>> modifying the domain admins group membership, ... >>>>> Removed Modify permission ...
    (microsoft.public.windows.server.security)
  • Re: Restricting Domain Admins
    ... > Change the security on the adminSDHolder container so that domain admins ... > Modify Permissions ... >>> Removed Modify permission ... >>> Removed modify owner permission ...
    (microsoft.public.windows.server.security)
  • Re: Restricting Domain Admins
    ... Modify Permissions ... the settings I have changed stop domain admins from ... >> Removed Modify permission ... >> Removed modify owner permission ...
    (microsoft.public.windows.server.security)
  • Can not logon locally
    ... Domain Admins for the NT 4.0 domain has "Access this ... This shouldn't require a reboot, ... >with an account from the nt4 domain but everytime i try ... >i open the local security policy and added domain admins ...
    (microsoft.public.win2000.security)