Re: prevent local administrator from logging in through Terminal Service

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 06/24/04


Date: Thu, 24 Jun 2004 06:14:40 GMT

I use TS for remote admin on a domain controller so I may not be quite right about
this but see if you have the option in the administrators account/Terminal Services
to disable the ability to logon via TS. Also check in Terminal Services
Configuration/connections - RDP-tcp/properties/permissions and grant the
administrator deny permissions for full control as an additional possibility. ---
Steve

"Tony" <tonyw@suse.stanford.edu> wrote in message
news:eEl7IXZWEHA.3492@TK2MSFTNGP10.phx.gbl...
> What can I do to prevent the local administrator of a win2k server from
> logging in via terminal service? I dont mean local administrator group. Just
> the user Administrator of the local server.
>
>



Relevant Pages

  • Re: Delegate Control
    ... what if it is a domain controller and does not have any local administrator ... "Pablo Vernocchi" wrote: ... >>or group must also be a member of the local machine administrator group. ...
    (microsoft.public.exchange.admin)
  • Re: Must all users be administrators?
    ... The familiar look of the AD objects tree you see in Group Policy Editor is ... This seems modestly confusing to an SBS Administrator because there's very ... those rights happen to be nearly unlimited. ... sit a workstation logged on as the Local Administrator, by default, there ...
    (microsoft.public.windows.server.sbs)
  • Re: More than one Administrator Account and Reinstalling OS on a D
    ... Some one has created a regular user account and may added that one to ... There is only one built-in administrator peer domain. ... FSMO roles are actually supposed to be transferred automatically during ... When you remove an existing Domain Controller within Active Directory, ...
    (microsoft.public.win2000.active_directory)
  • RE: AW: Security issue in Windows 2000?
    ... Change the local administrator name on the workstations i.e. local_admin ... If you want to prevent other local server ... > Evaluating SSL VPNs' Consider NEOTERIS, ...
    (Security-Basics)
  • Re: Windows NT Offline Password Editor - NT Domain Controllers
    ... domain controller and use it to gain access to the domain by changing the ... I tried the method described and was able to get domain administrator access ... has to be entered to gain access to the operating system before user logon. ... > local administrator account can be changed on NT workstations, ...
    (microsoft.public.security)