| Author |
Message |
Barry
Guest
|
Posted:
Tue Nov 08, 2005 5:27 pm Post subject:
Disable Remote Desktop for Administrator account.... |
|
|
Hi, This probably sounds a little unusual but is there a way I can prevent
logon via Remote Desktop using the local Administrator account?
I realize the default behavior in Windows is to automatically enable Remote
Desktop logon for any member of the Administrators group, but removing the
local Administrator account from the Administrators group is not an option
for me.
Thanks,
Barry |
|
| Back to top |
|
 |
Barry
Guest
|
Posted:
Tue Nov 08, 2005 5:27 pm Post subject:
RE: Disable Remote Desktop for Administrator account.... |
|
|
I should have dug further before I posted. I found a solution and thought I
would post it here in case anyone else has the need for this type of
configuration.
All I did was set the Local Policy on the target machine to deny Terminal
Server access to the local Administrator account (duh!) You can add/remove
local and Domain accounts for this policy as necessary using this method and
no need to modify local group memberships.
"Barry" wrote:
| Quote: | Hi, This probably sounds a little unusual but is there a way I can prevent
logon via Remote Desktop using the local Administrator account?
I realize the default behavior in Windows is to automatically enable Remote
Desktop logon for any member of the Administrators group, but removing the
local Administrator account from the Administrators group is not an option
for me.
Thanks,
Barry |
|
|
| Back to top |
|
 |
Steven L Umbach
Guest
|
Posted:
Wed Nov 09, 2005 1:28 am Post subject:
Re: Disable Remote Desktop for Administrator account.... |
|
|
It sounds like you configured the user rights for allow logon through
terminal services or deny logon through terminal services. By default the
allow logon through terminal services user right includes administrators and
remote desktop users. --- Steve
"Barry" <Barry@discussions.microsoft.com> wrote in message
news:048280EB-D04A-4A9F-8A0D-7CEE282D1959@microsoft.com...
| Quote: | I should have dug further before I posted. I found a solution and thought
I
would post it here in case anyone else has the need for this type of
configuration.
All I did was set the Local Policy on the target machine to deny Terminal
Server access to the local Administrator account (duh!) You can
add/remove
local and Domain accounts for this policy as necessary using this method
and
no need to modify local group memberships.
"Barry" wrote:
Hi, This probably sounds a little unusual but is there a way I can
prevent
logon via Remote Desktop using the local Administrator account?
I realize the default behavior in Windows is to automatically enable
Remote
Desktop logon for any member of the Administrators group, but removing
the
local Administrator account from the Administrators group is not an
option
for me.
Thanks,
Barry |
|
|
| Back to top |
|
 |
|
|
|
|