Click here to get back home

Deny Network access via a Policy - Help!!!

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Deny Network access via a Policy - Help!!! @nirgendwo 09-02-2005
Posted by @nirgendwo on September 2, 2005, 2:48 am
Please log in for more thread options
Hi Guys,

We are setting up a policy to lock down the TS/RDP sessions for out remote
customers, and I have hit a problem, if I create a shortcut to a share on the
deskop they can access it fine and get to documents inside it...etc. However
if the click the "Up a folder button" again and again it just keeps going and
you eventually get to our domain and can see and access all machines within
it including servers. How can I stop this from happening, either by hiding
the domain or preventing browse access to it via a security policy or reg
hack, its windows 2003 server ent, I thought there was an Item that prevents
access to the domain in the security policy but I cant xseem to find it.

Thanks guys!

Antiny Clifford
IT
Education Direct


Posted by Roger Abell [MVP] on September 5, 2005, 11:00 pm
Please log in for more thread options
So as I read your post
- you are providing external customers with terminal services login
to your internal corporate forest
- you are letting them log in with domain accounts
- your internal machines are at default with Domain Users in the
machine local Users group
- your machines share with default grants to Everyone, or with
other broad grant such as to Domain Users, and the sharing
machines do not restrict the machines with which they communicate

That sounds like four things that maybe should be each examined
for alternatives in order to segment and protect your assests.

--
Roger Abell
Microsoft MVP (Windows Server : Security)
MCDBA, MCSE W2k3+W2k+Nt4
> Hi Guys,
>
> We are setting up a policy to lock down the TS/RDP sessions for out remote
> customers, and I have hit a problem, if I create a shortcut to a share on
> the
> deskop they can access it fine and get to documents inside it...etc.
> However
> if the click the "Up a folder button" again and again it just keeps going
> and
> you eventually get to our domain and can see and access all machines
> within
> it including servers. How can I stop this from happening, either by hiding
> the domain or preventing browse access to it via a security policy or reg
> hack, its windows 2003 server ent, I thought there was an Item that
> prevents
> access to the domain in the security policy but I cant xseem to find it.
>
> Thanks guys!
>
> Antiny Clifford
> IT
> Education Direct




Similar ThreadsPosted
Is It Safe to Deny Administrators Login by Network to Domain Controller? January 13, 2007, 3:00 am
Deny folder access for administrators January 24, 2006, 4:28 am
Deny Specific Subnet Access to DC July 17, 2006, 4:06 pm
Controlling access through a remote access policy August 19, 2005, 7:00 am
Network access quarantine control January 27, 2006, 12:27 pm
VBScript program loses network access September 15, 2005, 5:10 am
Server 2003 network directory access March 13, 2008, 4:56 pm
Domain Security Policy -> Access is denied for Administrator July 17, 2006, 7:04 am
Questions on Authenticated Users and Access This Computer From Network User Right July 2, 2006, 8:38 pm
"Network Service" account is UNABLE to write to a network shared folder April 18, 2007, 7:01 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap