Click here to get back home

Secure VPN access...?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Secure VPN access...? MarkW 06-21-2005
Posted by MarkW on June 21, 2005, 5:13 pm
Please log in for more thread options
Greetings,

I recently upgraded to SBS 2003std, and am needing to allow a vendor remote
access to the server to do some software updates on their program. I had no
problem setting up the user, adding them to the Mobile Users group, and
connecting to the Remote Web Workplace. Unfortunately, at this point, the
user has no access to server, and thus, is unable to upload program updates
and troubleshoot problems.

In researching this a bit, it appears that I have to grant the user Domain
Admin privledges. Is this correct? I'm a bit concerned, in that this person
will then have full access to the server. Is there a more secure way to
allow this remote user upload/file access to the server, or is this my only
option?

Thanks in advance for your advice and feedback.
--
Thanks,
MarkW


Posted by Roger Abell on June 22, 2005, 7:11 am
Please log in for more thread options
In order to log in it is likely just as Slav stated, which could be
fixed by adding the account in a GPO liked to the Domain Controllers
OU to the Security Policy to Log on locally.

However, that lets them into your SBS server, at which point they
could still tromp about more than you might wish (shared data, etc.).
Also, that may be insufficient for them to do their work updating
and troubleshooting their application. Membership in the group
Administrators would let them in and let them work but would
keep them from going off box to other machines in your environ
(at least keep them from accesses not granted to Domain Users).

--
Roger Abell
Microsoft MVP (Windows Security)

> Greetings,
>
> I recently upgraded to SBS 2003std, and am needing to allow a vendor
remote
> access to the server to do some software updates on their program. I had
no
> problem setting up the user, adding them to the Mobile Users group, and
> connecting to the Remote Web Workplace. Unfortunately, at this point, the
> user has no access to server, and thus, is unable to upload program
updates
> and troubleshoot problems.
>
> In researching this a bit, it appears that I have to grant the user Domain
> Admin privledges. Is this correct? I'm a bit concerned, in that this
person
> will then have full access to the server. Is there a more secure way to
> allow this remote user upload/file access to the server, or is this my
only
> option?
>
> Thanks in advance for your advice and feedback.
> --
> Thanks,
> MarkW




Posted by S. Pidgorny on June 22, 2005, 7:30 pm
Please log in for more thread options
Probably the right to log on locally to the server would be sufficient -
often that's the only bit required in scenarios where "Admin works but User
doesn't". Don't ever make people admins unnecessarily. I would also
recommend asking in the SBS groups.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

> Greetings,
>
> I recently upgraded to SBS 2003std, and am needing to allow a vendor
remote
> access to the server to do some software updates on their program. I had
no
> problem setting up the user, adding them to the Mobile Users group, and
> connecting to the Remote Web Workplace. Unfortunately, at this point, the
> user has no access to server, and thus, is unable to upload program
updates
> and troubleshoot problems.
>
> In researching this a bit, it appears that I have to grant the user Domain
> Admin privledges. Is this correct? I'm a bit concerned, in that this
person
> will then have full access to the server. Is there a more secure way to
> allow this remote user upload/file access to the server, or is this my
only
> option?
>
> Thanks in advance for your advice and feedback.
> --
> Thanks,
> MarkW




Similar ThreadsPosted
cannot access a secure web site September 27, 2005, 1:15 pm
Secure FTP June 15, 2005, 2:16 pm
is ssl secure enough ? June 15, 2005, 11:33 pm
Best way to secure August 20, 2007, 7:44 pm
TS Client - How Secure? July 10, 2005, 1:21 am
Secure SFU Server for NIS November 22, 2006, 4:58 am
Secure SSL with LDAP and AD May 20, 2008, 11:23 am
Secure Remote Desktop August 10, 2006, 11:00 pm
WPA2 with PEAP-TLS - How secure is it? November 5, 2006, 7:42 am
Best practice to secure server????? November 28, 2006, 4:35 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap