Locking down TS on Domain Controller...



Good morning!

Okay. I know that this is not suggested. I know that it is not
recommended. I am aware of the security risks. I know that there are
several people who will kill me when they read this. The environments that
I manage are all very small and have a limited budget for 'computer stuff'.

I have a client (very small) that has a 64-bit Domain Controller (Windows
Server 2003 x64 running on a Dell PowerEdge 800). They have a remote office
and they want to use Terminal Services so that those five users in the
remote office can access vital information. Pretty much nothing else is of
interest to them.

So, I would like to lock down the Terminal Server experience for those five
users. Just as a point of interest, I have done this several times in a
WIN2000 environment and once in a WIN2003 environment (following the usual
MS KB Articles and Patrick Rouse's suggestions on the File System - all
works very very well). The *MAJOR* difference was that in each case the TS
was a member server, not a Domain Controller.

I should mention that I am playing in the lab right now. The only
difference between the lab and the production environment is that I am
sitting on a 32-bit Server right now. I will not be able to use the GPMC
when it comes time to do this on the production server as the GPMC does not
run on 64-bit Servers....

Everything (minus the TS Lockdown GPO) is working. So, there are no other
issues (well, none that I can see). I have a WINXP Pro SP2 client and I log
on to that using the user account object of one of the five TS Users and
then use RDP to connect to the Terminal Server. Everything is good (again,
minus the lockdown GPO).

Here is what I have done:

Follow MS KB278295 (create the GPO, link it to the Domain Controllers OU - I
know, I know, use gpupdate /force and then log on as one of the users. None
of the settings set by the 'TS Lockdown' GPO take place). I have done this,
as I already mentioned, in production environments several times as well as
in the lab hundreds of times. When I run RSOP.MSC on the Domain Controller
and change the focus (from Administrator to TSUser1) I do not see any of the
settings set in the 'TS Lockdown'.

Oh, one more point - on the SECURITY tab of the GPO I removed Authenticated
Users and 1) replaced it with a security group that I created (which
contains the user account objects) - nothing, 2) replaced that security
group with 'Remote Desktop Users' (just to see if that had any effect) -
nothing, and 3) removed the group and replaced it with each individual user
account object - nothing! After each of the mentioned changes I used
gpupdate /force and, when nothing happened, I rebooted the Domain Controller
(again, in the lab right now). Still nothing.

There is nothing in the event logs to indicate the GPO failed for such and
such a reason. This is a bit odd!

I guess that because this is a Domain Controller I am getting stupid!

Does anyone have any suggestions?

Thanks all,

--
Cary W. Shultz
Roanoke, VA 24012


.



Relevant Pages

  • RE: IE Security Group Policy
    ... username and password to access the Companyweb and the GPO did not apply on ... In the Security filtering of the GPO, please select the user account or ... Step 2: Check the IIS settings on the SBS Server: ...
    (microsoft.public.windows.server.sbs)
  • Re: Group Policy is now inhibiting the Administrator account
    ... under Group Policy Objects - those are the individual GPOs. ... You can apply any given GPO to one or more OUs, ... I use all of the default security in SBS, ... log on to the server with your own account. ...
    (microsoft.public.windows.server.sbs)
  • RE: Running TS on DC
    ... but create a GPO that will apply to the server: ... Security - Security Zones and Content Ratings ... can force the same settings to all that logs into it. ... services" to enable user account to login to the Dc/terminal server. ...
    (microsoft.public.windows.terminal_services)
  • Re: User Rights required to Start and Stop the spooler service?
    ... Microsoft MVP - Windows Security ... I used an existing GPO, basically all it does is set the spooler ... been applied but it does not show the security settings in the report. ... Is computer account of the server in that OU? ...
    (microsoft.public.windows.server.general)
  • RE: Win 200 TS in Win 2003 Domain
    ... You need to have the security right to allow you to log on - check there. ... Well now the TS server will not allow anyone ... > but admin groups to logon interactivly. ... > had in the old GPO in to the 2003 GPO, plus I added the appropriate one's for ...
    (microsoft.public.win2000.termserv.apps)