Click here to get back home

Securing Remote Desktop To Server

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Securing Remote Desktop To Server Harry 08-11-2005
Posted by Harry on August 11, 2005, 10:30 am
Please log in for more thread options
I need to give someone console access to our server because one of the
server applications is only managable from the server. I don't want to make
the person an admin over the server, but do need to have them login via
remote desktop from their workstation. What is the best way to set this up?




Posted by Roger Abell on August 11, 2005, 8:21 am
Please log in for more thread options
First - do you trust them?
There are times when vulnerabilities have existed, and likely will
in the future again, where a key part of their exploitation is the ability
to log in locally (or via TS / RD).

You can make them a Users member only, perhaps restrict them from
sensitive areas on the server also, and yet grant them RD login on
the server. It sounds like this is W2k3 as you are saying RD, in which
case just make sure use of RD login is enabled and that their restricted
account is a member of predefined Users and of the RD login groups.

When I get forced into this situation, I also configure TS on the server
so that the RD user cannot hog the allowed RD connections - setting
TS so that disconnected sessions are killed after a short time (hr +/-)
and so that idle sessions are also killed after a time.

--
Roger Abell
Microsoft MVP (Windows Security)
MCSE (W2k3,W2k,Nt4) MCDBA
> I need to give someone console access to our server because one of the
> server applications is only managable from the server. I don't want to
make
> the person an admin over the server, but do need to have them login via
> remote desktop from their workstation. What is the best way to set this
up?
>
>




Posted by Harry on August 11, 2005, 3:21 pm
Please log in for more thread options
Do I trust this person? I don't trust anyone but myself when it comes to
console access to a server, but I have no choice in this one. It's coming
from the "top brass". Yes, I am running W2k3. Thanks for the tips. I'll
test it out before turning it over to the new app. admin.




> First - do you trust them?
> There are times when vulnerabilities have existed, and likely will
> in the future again, where a key part of their exploitation is the ability
> to log in locally (or via TS / RD).
>
> You can make them a Users member only, perhaps restrict them from
> sensitive areas on the server also, and yet grant them RD login on
> the server. It sounds like this is W2k3 as you are saying RD, in which
> case just make sure use of RD login is enabled and that their restricted
> account is a member of predefined Users and of the RD login groups.
>
> When I get forced into this situation, I also configure TS on the server
> so that the RD user cannot hog the allowed RD connections - setting
> TS so that disconnected sessions are killed after a short time (hr +/-)
> and so that idle sessions are also killed after a time.
>
> --
> Roger Abell
> Microsoft MVP (Windows Security)
> MCSE (W2k3,W2k,Nt4) MCDBA
>> I need to give someone console access to our server because one of the
>> server applications is only managable from the server. I don't want to
> make
>> the person an admin over the server, but do need to have them login via
>> remote desktop from their workstation. What is the best way to set this
> up?
>>
>>
>
>




Posted by keith on August 12, 2005, 10:54 pm
Please log in for more thread options
Is it possible to give them another account and place it in another OU with
a serious GP lockdown i.e. only with the access rights to that application?

Just a thought...

Cheers
Keith

>I need to give someone console access to our server because one of the
>server applications is only managable from the server. I don't want to make
>the person an admin over the server, but do need to have them login via
>remote desktop from their workstation. What is the best way to set this up?
>




Similar ThreadsPosted
Remote Desktop Protocol Server Private Key Disclosure Vulnerability March 30, 2008, 9:34 am
Windows Small Business Server 2003 Premium and Remote Desktop June 8, 2006, 6:09 pm
Remote desktop February 21, 2006, 3:25 pm
SSL and Remote Desktop February 27, 2008, 7:53 pm
Can connect via Remote Desktop September 26, 2005, 12:36 pm
remote desktop security February 18, 2006, 5:38 pm
Windows Remote Desktop April 16, 2006, 7:17 am
Secure Remote Desktop August 10, 2006, 11:00 pm
RDP: remote desktop issues September 23, 2007, 3:13 pm
Remote Desktop Protocol October 29, 2007, 5:16 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap