Group Policy Server Lockdown
Windows Server Forum Index Windows Server
Server discussion on Windows platform.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web winserverhelp.com
Group Policy Server Lockdown

 
Post new topic   Reply to topic    Windows Server Forum Index -> Active Directory
Author Message
Hiro
Guest





Posted: Thu Nov 03, 2005 5:50 pm    Post subject: Group Policy Server Lockdown Reply with quote

I have a mix of windows 2000/windows 2003 servers in an OU. I need to setup
Group Policy to allow a group of users (web_admin) the ability to logon
through a remote session to manage these servers. All other users not in the
web_admin group should not be able to logon to this server. What is the best
method to do this?
Back to top
Paul Williams [MVP]
Guest





Posted: Fri Nov 04, 2005 9:51 am    Post subject: Re: Group Policy Server Lockdown Reply with quote

Modify the logon locally and logon via terminal services rights for this
server or servers. Do this by filtering the GPO to the servers in question,
and only granting these rights to domain local groups that you create. Then
pop the users you want to have access into these groups. Also, leave
administrators in there.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net
Back to top
Hiro
Guest





Posted: Fri Nov 04, 2005 9:50 pm    Post subject: Re: Group Policy Server Lockdown Reply with quote

Which policies exactly need to be edited?

"Paul Williams [MVP]" wrote:

Quote:
Modify the logon locally and logon via terminal services rights for this
server or servers. Do this by filtering the GPO to the servers in question,
and only granting these rights to domain local groups that you create. Then
pop the users you want to have access into these groups. Also, leave
administrators in there.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net


Back to top
Chriss3 [MVP]
Guest





Posted: Mon Nov 07, 2005 1:50 am    Post subject: Re: Group Policy Server Lockdown Reply with quote

Computer Configuration\Windows Settings\Local Policies\User Rights
Assignment\Allow log on through Terminal Services


--
Regards
Christoffer Andersson
Microsoft MVP - Directory Services

No email replies please - reply in the newsgroup
------------------------------------------------
http://www.chrisse.se - Active Directory Tips

"Hiro" <Hiro@discussions.microsoft.com> skrev i meddelandet
news:7E602213-9CAC-4F97-AC96-47B26921FD6A@microsoft.com...
Quote:
Which policies exactly need to be edited?

"Paul Williams [MVP]" wrote:

Modify the logon locally and logon via terminal services rights for this
server or servers. Do this by filtering the GPO to the servers in
question,
and only granting these rights to domain local groups that you create.
Then
pop the users you want to have access into these groups. Also, leave
administrators in there.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net


Back to top
Hiro
Guest





Posted: Mon Nov 07, 2005 5:50 pm    Post subject: Re: Group Policy Server Lockdown Reply with quote

Have this policy updated with the correct group (webadmin). Also I have every
user that is in webadmin group in the remote desktop user group. Still no
luck logging into servers.

I ended up logging on the webserver and adding the webadmin group to the
Remote Users locally. This setup worked.

Shouldn't I just be able to do this through a GPO without having to make any
changes locally? Could it have something to do with group policy not
applying?

"Chriss3 [MVP]" wrote:

Quote:
Computer Configuration\Windows Settings\Local Policies\User Rights
Assignment\Allow log on through Terminal Services


--
Regards
Christoffer Andersson
Microsoft MVP - Directory Services

No email replies please - reply in the newsgroup
------------------------------------------------
http://www.chrisse.se - Active Directory Tips

"Hiro" <Hiro@discussions.microsoft.com> skrev i meddelandet
news:7E602213-9CAC-4F97-AC96-47B26921FD6A@microsoft.com...
Which policies exactly need to be edited?

"Paul Williams [MVP]" wrote:

Modify the logon locally and logon via terminal services rights for this
server or servers. Do this by filtering the GPO to the servers in
question,
and only granting these rights to domain local groups that you create.
Then
pop the users you want to have access into these groups. Also, leave
administrators in there.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net





Back to top
Paul Williams [MVP]
Guest





Posted: Tue Nov 08, 2005 9:51 am    Post subject: Re: Group Policy Server Lockdown Reply with quote

You need both logon locally and logon using terminal services. The RDP
group has these rights already. You may also need to configure the
permissions on the RDP Protocol (in TS config). I can't remember. The RDP
group also has the necessary permissions here.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net
Back to top
Hiro
Guest





Posted: Tue Nov 08, 2005 5:51 pm    Post subject: Re: Group Policy Server Lockdown Reply with quote

I am able to give the Active Directory group (webadmin) access if I change TS
Config locally on each server. This just seems backwards because if there is
a group policy it should already apply to the server.

"Paul Williams [MVP]" wrote:

Quote:
You need both logon locally and logon using terminal services. The RDP
group has these rights already. You may also need to configure the
permissions on the RDP Protocol (in TS config). I can't remember. The RDP
group also has the necessary permissions here.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net


Back to top
Paul Williams [MVP]
Guest





Posted: Sun Nov 13, 2005 1:50 pm    Post subject: Re: Group Policy Server Lockdown Reply with quote

The permissions on the RDP object are defined to allow the remote desktop
users. Adding the user to this group (and obviously allowing for
replication and the user to refresh his/ her access token) should sort this.

I don't know if there are GPO settings that can configure the permissions of
the RDP object for you - I've never looked. It might be worth asking about
this in the Terminal Services group.

Otherwise, it's the manual process you mentioned :-(

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net
Back to top
 
Post new topic   Reply to topic    Windows Server Forum Index -> Active Directory All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




New Topics Powered by phpBB