Re: How hard is it to config Win2003 to serve a single app and offer users little else?



Hi Vera and thanks again for that pointer. I see that the RD Connection
dialog has a Programs tab that lets one start up a program when the TS
session is initiated. But why couldn't the user just remove that setting
from their RD Connection and then start up with the desktop and all? I
know perms have to be controlled in any case. But is there something
basic I'm missing that would prevent a RD user from only being able to
start just one app? I was expecting a setting on the server end. In AD
for each user there is an environment tab but I don't think it locks
down the user to just one app they can run.

In article <Xns9732F0CBAECADveranoesthemutforsse@xxxxxxxxxxxxx>,
vera.noest@xxxxxxxxxxxxxxxxxxxxxxxxx says...
> You can configure your Terminal Server to start a specific
> application upon connection. This means that users will not even
> see the TS desktop, but will be logged of their session
> automatically when they exit the application.
> Besides that, you can (and should!) use a Group Policy to restrict
> what users can do on your TS and NTFS permissions on the file
> system to lock it down further.
>
> 278295 - How to lock down a Windows Server 2003 or Windows 2000
> Terminal Server session
> http://support.microsoft.com/?kbid=278295
>
> _________________________________________________________
> Vera Noest
> MCSE, CCEA, Microsoft MVP - Terminal Server
> TS troubleshooting: http://ts.veranoest.net
> ___ please respond in newsgroup, NOT by private email ___
>
> kiln <kiln@xxxxxxxxxxxxxx> wrote on 20 dec 2005 in
> microsoft.public.windows.terminal_services:
>
> > New to ts, more or less. I have an application that I'd like to
> > offer via terminal services to users over the internet. I've
> > dialed in to ts boxes using remote desktop, but I've always be a
> > person with admin priviledges, so I could do almost anything on
> > that machine. For the use I'm thinking about now, I'd have a
> > bunch of users dialing in in order to use one application that
> > I've designed. I'd not want those users to be able to start IE,
> > reboot the pc, use windows explorer, those sorts of tasks that
> > regular users can do. I'm pretty sure it's possible to restrict
> > those 'user' remote desktop sessions to the minimum needed for
> > my app, but how hard is it to do? Does one config for this
> > manually or are there like scripts that can config for me? I'm
> > likley to have a dedicated box for this, so I'd be able to
> > config as needed. I tried searching for this in the newgroup but
> > I couldn't come up with the right terms to query for, so I
> > apologise if this topic has been asked too many times.
>
.



Relevant Pages

  • Re: Automate Install/Connection - VPN/TS Sessions
    ... If you use Terminal Server, ... requirements with VPN & Fat Client vs. Terminal Server/Citrix connection. ... >> installed on the Terminal Server, then when they launch the Remote Desktop ...
    (microsoft.public.win2000.termserv.clients)
  • Re: Can I access/run programs remotely that are stored on the serv
    ... It is vary easy to mistake Terminal Server with Remote Desktop. ... if its SBS 2003 you can NOT use it in Terminal Server application ... >> as long as you have a decently fast connection... ...
    (microsoft.public.windows.server.sbs)
  • Re: TS admin session
    ... in Terminal Services Configuration ... - tcp-rdp connection. ... MCSE, CCEA, Microsoft MVP - Terminal Server ... There can only be a single console session. ...
    (microsoft.public.windows.terminal_services)
  • Re: terminal session dropping out
    ... Just found out that they also have voip on their connection and its only 128k, yesterday and today there hasn't been as many dropped connections because one person was out of the office and that would mean just that much more available bandwidth. ... be capable of cutting the session after some idle time. ... the rdp-tcp connection in terminal services configuration was set to override user settings and end a disconnected session in 5 minutes, disconnect an active connection after 1 day and an idle session of 3 hours. ... 216783 - Unable to Completely Disconnect a Terminal Server Connection ...
    (microsoft.public.windows.terminal_services)
  • Re: Session "Active" even if connection is broken.
    ... to enable keepalives on the TS or the remote workstation? ... timed-out connection setting recommended in KB21783 ... prior to cutting off the session? ... > 216783 - You cannot completely disconnect a Terminal Server ...
    (microsoft.public.windows.terminal_services)