MSTerminalServices.org Forums

Forums Home | FAQ | Search | Profile | Private Messages | Log in/Register/Password

Terminal Server Lockdown

Page 1 of 1
Next:  Microsoft Terminal Services: Really Simple TS + IE  
Author Message
spencer805




Joined: Feb 27, 2008
Posts: 2



(Msg. 1) Posted: Wed Feb 27, 2008 5:19 pm
Post subject: Terminal Server Lockdown

I am having problems getting GPO to be accepted on my TS users. Here is what I have done, and a glimpse of my system.
1. Windows 2000 DC, soon to be taken out of service
2. Windows Server 2003 DC, running AD, DHCP, WINS, DNS
3. Windows Server 2003 Terminal Server, member server
4. Windows Server 2003 Exchange Server, member server

I want to lock down TS Users so here is what I have done.
A. Created an OU called School Based Counselors
B. From AD, placed the Terminal Server computer in the above OU
C. Created a GPO called TS Loopback & linked it to School Based Counselors
D. enabled User Group Policy looback processing mode, mode= replace
E. Created another GPO called SBC
F. Enabled Prohibit access to the Control Panel
G. Created global group called School Counselors, filtered/ added it in the above OU
H. Added a test user to the global group School Counselors
I. On the Terminal Server, placed the global group (School Counselors) into the local Remote Desktop Users Group.
L. Logged on as the test user, however I am still able to access Control Pane.

Where did I go wrong in this scenario.

Thank you in advance


Last edited by spencer805 on Wed Feb 27, 2008 5:40 pm; edited 1 time in total
Back to top
Send e-mail Login to vote
vera_noest




Joined: May 27, 2007
Posts: 205

Location: Sweden

(Msg. 2) Posted: Wed Feb 27, 2008 5:35 pm
Post subject:

I can see only one thing in your list which doesn't seem right:

Quote:
G. Created global group called School Counselors, linked it to the above OU


You cannot "link" a security group to an OU. You can place the security group in the OU, but that does not do what you want.

What you have to do is to use the security filtering of the GPO to include the security group, and give them at least Read and Apply this Policy rights. If you remove the default "Authenticated Users" group from the security filtering of the GPO, you also have to add the Terminal Server's computer account in the security filtering (normally, the TS machine account is part of the Authenticated Users group).

You can use Resultant Set of Policies to see which GPOs are applied to your test user when logged on to your TS.
Back to top
Send e-mail Login to vote
spencer805




Joined: Feb 27, 2008
Posts: 2



(Msg. 3) Posted: Wed Feb 27, 2008 5:49 pm
Post subject: [Login to view extended thread Info.]

Thanks Vera,
Please see my corrected scenario regarding item G.

You mentioned give read and apply rights to this GPO. How exactly do I do this?

One thing I want to clarify. I put the terminal server computer object in the OU via active directory, not GPMC. I noticed that I can add the computer via GPMC and it gives something like this in the filtered area: TRMSRV$ [abc\TRMSRV$]. I get the same resultes if I move the terminal server computer out of the OU via AD and place it in the Security Filtering via GPMC or vice versa, or both.
Back to top
Send e-mail Login to vote
vera_noest




Joined: May 27, 2007
Posts: 205

Location: Sweden

(Msg. 4) Posted: Thu Feb 28, 2008 5:13 pm
Post subject: [Login to view extended thread Info.]

Those are 2 completely different things, and they have to be done both for the TS!

You need to put the TS account into the OU, in AD. This ensures that the policy can be applied to the TS at all.
It does not matter at all where the School Based Counselors security group is located in AD, since policies cannot be linked to security groups.

Then you have to modify the security filtering in the GPMC: add the TS machine account to it, as well as the School Based Counselors security group. Then go the Advanced - Security tab in GPMC and ensure at least Read and Apply this Policy rights for both the TS account and the School Based Counselors security group.
Back to top
Send e-mail Login to vote
Display posts from previous:   
    All times are: Eastern Time (US & Canada) (change) Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Looking for more Terminal Services info?

Sign up to the MSTerminalServices.org Monthly Newsletter, written by Terminal Server MVP & Citrix CTP Stefan Vermeulen, containing news, tips, interviews, links of the month and much more. Subscribe today and don't miss a thing!

Become an MSTerminalServices.org member!

Discuss your Terminal Services & Citrix issues with thousands of other SBC experts. Click here to join!

Community Area

Log in | Register