RDP client secuirty - disabling mapped drives



I have a vendor who wants our users to connect to a Windows 2003 Terminal Server (outside of our corporate control) in order to run a medical database application.

A requirement of this process is that our users (and other users in other health care companies all over the country) have to connect their drives to this foreign system. This raised a red flag immediately. The vendor is willing to work out other ways of file transfer, but in the meantime this is such a severe security hole we would like to globally disable this "feature" of the XP RDP client.

Unless I'm missing something, there appears to be no way to restrict this on the client side. There is an AD (Computer) Group Policy for "Do not allow drive redirection" but this appears to be a server-side policy. Since the server is outside our control, this policy is not going to work.

Has anyone run across this and has anyone found a way to prevent users from opening up this HUGE, GAPING security hole?
.



Relevant Pages

  • RDP Security - Preventing clients from mapping drives
    ... I have a vendor who wants our users to connect to a Windows 2003 Terminal Server (outside of our corporate control) in order to run a medical database application. ...
    (microsoft.public.windows.terminal_services)
  • Re: RDP client secuirty - disabling mapped drives
    ... Terminal Server (outside of our corporate control) in order to run a ... this "feature" of the XP RDP client. ... redirection" but this appears to be a server-side policy. ... server is outside our control, this policy is not going to work. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: How to allow users to create groups and shares
    ... Add the user/group to the Computer configuration, windows settings, security settings, Local policies, "Allow logon locally" in the Default domain controllers policy and on a existing or new created policy for the member servers. ... Filtering: Not Applied ... check with GPMC on the server or from a client the policy settings. ...
    (microsoft.public.windows.server.active_directory)
  • Domain Controller Security Policy errors
    ... Security Policy or the Domain Controller Security Policy. ... The DC is also a print and file server. ... The domain controller for Group Policy operations is not available. ...
    (microsoft.public.win2000.active_directory)
  • RE: Cant set Local Security policies. They fail to save
    ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
    (microsoft.public.windows.server.sbs)