Click here to get back home

Disallowing console login on w2k3

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Disallowing console login on w2k3 styles.q 05-20-2007
Posted by styles.q on May 20, 2007, 9:41 pm
Please log in for more thread options
Is it possible to disallow console login for certain users/groups?

By console login in mean using RD like so:

mstsc /v:box1 -console

The scenario is that I would like for only one user on the box to be
allowed to login to the console (session 0). This is because the box
is running an application that unfortunately cannot be run as a
service, thus we need to preserve the console login and do not want
any other user assuming session 0.

I know you can disable kicking off an admin logged in to session 0 in
gpedit, but i would like to go one step further and explicity deny the
right to all users except for one.

Is it possible?

Thanks
JS


Posted by Paul Bergson [MVP-DS] on May 23, 2007, 8:25 am
Please log in for more thread options
I don't know of anyway where you can explicitly disallow a user to use the
console yet be able to logon to the box remotely. The only way I know is
don't allow remote access, via the rdp configuration.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

> Is it possible to disallow console login for certain users/groups?
>
> By console login in mean using RD like so:
>
> mstsc /v:box1 -console
>
> The scenario is that I would like for only one user on the box to be
> allowed to login to the console (session 0). This is because the box
> is running an application that unfortunately cannot be run as a
> service, thus we need to preserve the console login and do not want
> any other user assuming session 0.
>
> I know you can disable kicking off an admin logged in to session 0 in
> gpedit, but i would like to go one step further and explicity deny the
> right to all users except for one.
>
> Is it possible?
>
> Thanks
> JS
>



Similar ThreadsPosted
Disallowing console login May 20, 2007, 9:41 pm
access to thw WINS management console denied May 31, 2005, 3:39 pm
AzMan: Has anyone created an HTML/Web management console as an alternative to the AzMan MMC? January 4, 2006, 3:18 pm
Login Script Question - Failed Login Count, Location, and Method October 5, 2005, 6:28 pm
AzMan & W2k3 SP1 problem... June 30, 2005, 7:42 am
Kerberos/ASP/Delegation/W2K3 July 19, 2005, 2:24 pm
IPSEC, W2k3, Client-to-DC August 8, 2005, 10:36 am
NTLM issue with W2K3 April 28, 2006, 10:47 am
Backing up roaming profiles on W2K3 January 11, 2006, 1:37 pm
W2K3 & VPN blocking access to server May 17, 2006, 9:10 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap