Click here to get back home

Single Server access to stand alone servers within domain

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Single Server access to stand alone servers within domain Robert 06-26-2008
Posted by Robert on June 26, 2008, 6:49 pm
Please log in for more thread options
I need to setup a 2003 Terminal Server for an outside agency. This server
needs to access our TS License Server and another stand alone server within
our domain. I'd don't want to add the server to our domain or create a new
domain for it. If I make the admin password the same as our domain admin
password it works okay but I also get more access to the domain than I want.
What would be best practice for getting this single isolated server limited
access to only trhese two servers within the domain ?

Posted by S. Pidgorny on June 27, 2008, 7:33 am
Please log in for more thread options
Why not to add the server to your domain? That gives you functionality to
have the required access restrictions...

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *


>I need to setup a 2003 Terminal Server for an outside agency. This server
> needs to access our TS License Server and another stand alone server
> within
> our domain. I'd don't want to add the server to our domain or create a new
> domain for it. If I make the admin password the same as our domain admin
> password it works okay but I also get more access to the domain than I
> want.
> What would be best practice for getting this single isolated server
> limited
> access to only trhese two servers within the domain ?



Posted by Robert on June 27, 2008, 12:09 pm
Please log in for more thread options
The server is hosting access for another company and I don't want the
possiblility of them accessing anything except the two servers in question. I
would feel more comfortable is they were just local server accounts and not
Domain accounts, but I'm not sure how you could give a local server user
account access to a domain server when that server is not part of the domain.

"S. Pidgorny <MVP>" wrote:

> Why not to add the server to your domain? That gives you functionality to
> have the required access restrictions...
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>
>
> >I need to setup a 2003 Terminal Server for an outside agency. This server
> > needs to access our TS License Server and another stand alone server
> > within
> > our domain. I'd don't want to add the server to our domain or create a new
> > domain for it. If I make the admin password the same as our domain admin
> > password it works okay but I also get more access to the domain than I
> > want.
> > What would be best practice for getting this single isolated server
> > limited
> > access to only trhese two servers within the domain ?
>
>
>

Posted by S. Pidgorny on June 29, 2008, 4:06 am
Please log in for more thread options
Generally a computer doesn't have to be a member of the domain for the users
to have access to domain resources (I can map drives on Windows server from
my Linux system, for example).

But in your scenario, in the end, you'll have to provide them with either a
domain account, or its credentials. ACLs on the resources and perhaps a
firewall will give you enough control. You can create a GPO with a security
policy that will disallow those external users log on intercatively or via
network to any other computers.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

> The server is hosting access for another company and I don't want the
> possiblility of them accessing anything except the two servers in
> question. I
> would feel more comfortable is they were just local server accounts and
> not
> Domain accounts, but I'm not sure how you could give a local server user
> account access to a domain server when that server is not part of the
> domain.
>
> "S. Pidgorny <MVP>" wrote:
>
>> Why not to add the server to your domain? That gives you functionality to
>> have the required access restrictions...
>>
>> --
>> Svyatoslav Pidgorny, MS MVP - Security, MCSE
>> -= F1 is the key =-
>>
>> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>>
>>
>> >I need to setup a 2003 Terminal Server for an outside agency. This
>> >server
>> > needs to access our TS License Server and another stand alone server
>> > within
>> > our domain. I'd don't want to add the server to our domain or create a
>> > new
>> > domain for it. If I make the admin password the same as our domain
>> > admin
>> > password it works okay but I also get more access to the domain than I
>> > want.
>> > What would be best practice for getting this single isolated server
>> > limited
>> > access to only trhese two servers within the domain ?
>>
>>
>>



Similar ThreadsPosted
"access denied" for members of Administrators, stand-alone server June 21, 2007, 1:48 pm
How to give “View” access to all my servers in my domain? October 3, 2005, 5:11 am
Windows 2003 Single Mode - Workstation Login says: DOMAIN (Win 200 January 10, 2006, 8:41 pm
Any MS security options for single server 2008 x64 as notebook OS? January 17, 2008, 7:12 pm
Security on a stand-alone windows 2003 Server August 8, 2005, 11:42 am
Allowing a Domain User Admin Rights to a Couple of Domain Servers June 29, 2005, 8:13 pm
Prevent access to server for computers not part of domain January 22, 2007, 11:56 pm
Windows domain user is sometimes denied access to server share October 2, 2006, 5:07 am
Trusted NT domain users have full access to 2K3 server shares January 23, 2007, 6:51 am
Can't access W2003R2 Servers with RDP via VPN June 15, 2006, 2:07 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap