Werbung: SecurityConsole.de verwaltet Ihre Computer mit Security Essentails aus der Cloud!
30 Tage kostenfrei testen und 20% Rabatt für Ihre Bestellung mit Promocode: WBF2685582
(Promocode gültig bis 31.12.2011)

Group:  English: Windows Server » microsoft.public.windows.terminal_services
Thread: Windows Server 2008 TS Error.

HTVi
TV Discussion Newsgroups

Windows Server 2008 TS Error.
S H A R I Q U E 11/3/2008 7:40:02 PM

I have created a Remote App programe in Windows Server 2008 TS.From Windows
XP client having latest RDC 6.x installed, i can run the application
successfully using Administrator account.When i try to run same application
using domain use account, i get error that "To log on to this remote
computer, you must be be granted the Allow log on through Terminal Services
right. By default, members of the Remote Desktop Users group have this
right...etc..."

i have added the domain user/computer account in Remote Desktop uses group
in AD even after that i am getting error.
what piece of configuration I am missing.bear in mind that i am runnin this
setup in VM with default number of TS licenses, that is, two.
Re: Windows Server 2008 TS Error.
Jeff Pitsch <jeff.pitsch.fake[ at ]jeffpitschconsulting.com> 11/3/2008 8:11:23 PM
Is the terminal server also a domain controller? If not, you need to
add the users to the Remote Desktop User group that is local to the
terminal server.

Jeff Pitsch
Microsoft MVP - Terminal Services

S H A R I Q U E wrote:
[Quoted Text]
> I have created a Remote App programe in Windows Server 2008 TS.From Windows
> XP client having latest RDC 6.x installed, i can run the application
> successfully using Administrator account.When i try to run same application
> using domain use account, i get error that "To log on to this remote
> computer, you must be be granted the Allow log on through Terminal Services
> right. By default, members of the Remote Desktop Users group have this
> right...etc..."
>
> i have added the domain user/computer account in Remote Desktop uses group
> in AD even after that i am getting error.
> what piece of configuration I am missing.bear in mind that i am runnin this
> setup in VM with default number of TS licenses, that is, two.
Re: Windows Server 2008 TS Error.
S H A R I Q U E 11/4/2008 6:52:06 AM
yeah the TS is also DC..i have figured it out after posting this
question..actually i need to modify default domain controller policy and
amend USER RIGHTS ASSIGNMENTS ...it will definitely work.

thanks..

"Jeff Pitsch" wrote:

[Quoted Text]
> Is the terminal server also a domain controller? If not, you need to
> add the users to the Remote Desktop User group that is local to the
> terminal server.
>
> Jeff Pitsch
> Microsoft MVP - Terminal Services
>
> S H A R I Q U E wrote:
> > I have created a Remote App programe in Windows Server 2008 TS.From Windows
> > XP client having latest RDC 6.x installed, i can run the application
> > successfully using Administrator account.When i try to run same application
> > using domain use account, i get error that "To log on to this remote
> > computer, you must be be granted the Allow log on through Terminal Services
> > right. By default, members of the Remote Desktop Users group have this
> > right...etc..."
> >
> > i have added the domain user/computer account in Remote Desktop uses group
> > in AD even after that i am getting error.
> > what piece of configuration I am missing.bear in mind that i am runnin this
> > setup in VM with default number of TS licenses, that is, two.
>
Re: Windows Server 2008 TS Error.
S H A R I Q U E 11/4/2008 12:07:00 PM
Now, i am able to logon using domain users thanks to modifcation of local
security policy.
i have installed word viewer on WIN2K8 and provided access to WINXP client
through TS RemoteApp Manager. I can run application at WINXP client
successfully.
one thing which is quite alarming is that after opening WordViewer at client
side.When i goto File/Open, it gives domain user access to root of c driver
and shows my local drive as network drive.
How can i prevent users from accessing drives of WIN2K8 server.??


"Jeff Pitsch" wrote:

[Quoted Text]
> Is the terminal server also a domain controller? If not, you need to
> add the users to the Remote Desktop User group that is local to the
> terminal server.
>
> Jeff Pitsch
> Microsoft MVP - Terminal Services
>
> S H A R I Q U E wrote:
> > I have created a Remote App programe in Windows Server 2008 TS.From Windows
> > XP client having latest RDC 6.x installed, i can run the application
> > successfully using Administrator account.When i try to run same application
> > using domain use account, i get error that "To log on to this remote
> > computer, you must be be granted the Allow log on through Terminal Services
> > right. By default, members of the Remote Desktop Users group have this
> > right...etc..."
> >
> > i have added the domain user/computer account in Remote Desktop uses group
> > in AD even after that i am getting error.
> > what piece of configuration I am missing.bear in mind that i am runnin this
> > setup in VM with default number of TS licenses, that is, two.
>
Re: Windows Server 2008 TS Error.
Jeff Pitsch <jeff.pitsch.fake[ at ]jeffpitschconsulting.com> 11/4/2008 12:34:34 PM
You can use group policy to hide the server drives. Are you familiar
with group policy?

Jeff Pitsch
Microsoft MVP - Terminal Services

S H A R I Q U E wrote:
[Quoted Text]
> Now, i am able to logon using domain users thanks to modifcation of local
> security policy.
> i have installed word viewer on WIN2K8 and provided access to WINXP client
> through TS RemoteApp Manager. I can run application at WINXP client
> successfully.
> one thing which is quite alarming is that after opening WordViewer at client
> side.When i goto File/Open, it gives domain user access to root of c driver
> and shows my local drive as network drive.
> How can i prevent users from accessing drives of WIN2K8 server.??
>
>
> "Jeff Pitsch" wrote:
>
>> Is the terminal server also a domain controller? If not, you need to
>> add the users to the Remote Desktop User group that is local to the
>> terminal server.
>>
>> Jeff Pitsch
>> Microsoft MVP - Terminal Services
>>
>> S H A R I Q U E wrote:
>>> I have created a Remote App programe in Windows Server 2008 TS.From Windows
>>> XP client having latest RDC 6.x installed, i can run the application
>>> successfully using Administrator account.When i try to run same application
>>> using domain use account, i get error that "To log on to this remote
>>> computer, you must be be granted the Allow log on through Terminal Services
>>> right. By default, members of the Remote Desktop Users group have this
>>> right...etc..."
>>>
>>> i have added the domain user/computer account in Remote Desktop uses group
>>> in AD even after that i am getting error.
>>> what piece of configuration I am missing.bear in mind that i am runnin this
>>> setup in VM with default number of TS licenses, that is, two.
Re: Windows Server 2008 TS Error.
S H A R I Q U E 11/4/2008 8:19:03 PM
I do Know about Group Policies to block access to certain Folder/Drives. Cant
I use any other method to achieve the same.It is security breach and any
technical user can play havoc with DC.I dont know it is default feature of
Terminal Service to expose drive into open or not.If it yes, then it is
colossal security flaw.what i mean there should be a prevention to local
drive of TS server.

regards


"Jeff Pitsch" wrote:

[Quoted Text]
> You can use group policy to hide the server drives. Are you familiar
> with group policy?
>
> Jeff Pitsch
> Microsoft MVP - Terminal Services
>
> S H A R I Q U E wrote:
> > Now, i am able to logon using domain users thanks to modifcation of local
> > security policy.
> > i have installed word viewer on WIN2K8 and provided access to WINXP client
> > through TS RemoteApp Manager. I can run application at WINXP client
> > successfully.
> > one thing which is quite alarming is that after opening WordViewer at client
> > side.When i goto File/Open, it gives domain user access to root of c driver
> > and shows my local drive as network drive.
> > How can i prevent users from accessing drives of WIN2K8 server.??
> >
> >
> > "Jeff Pitsch" wrote:
> >
> >> Is the terminal server also a domain controller? If not, you need to
> >> add the users to the Remote Desktop User group that is local to the
> >> terminal server.
> >>
> >> Jeff Pitsch
> >> Microsoft MVP - Terminal Services
> >>
> >> S H A R I Q U E wrote:
> >>> I have created a Remote App programe in Windows Server 2008 TS.From Windows
> >>> XP client having latest RDC 6.x installed, i can run the application
> >>> successfully using Administrator account.When i try to run same application
> >>> using domain use account, i get error that "To log on to this remote
> >>> computer, you must be be granted the Allow log on through Terminal Services
> >>> right. By default, members of the Remote Desktop Users group have this
> >>> right...etc..."
> >>>
> >>> i have added the domain user/computer account in Remote Desktop uses group
> >>> in AD even after that i am getting error.
> >>> what piece of configuration I am missing.bear in mind that i am runnin this
> >>> setup in VM with default number of TS licenses, that is, two.
>
Re: Windows Server 2008 TS Error.
Jeff Pitsch <jeff.pitsch.fake[ at ]jeffpitschconsulting.com> 11/4/2008 8:55:29 PM
It is a colossal security flaw to allow your users on the domain
controller. It's not MS"s fault you've gone against best practices and
decided to use your DC as a terminal server. there is a way to prevent
users access to the local drives and that is through group policy. It
is two settings you need to set and you are good to go. Is it perfect?
Nope but it's the best we have right now. If you are truly, TRULY
concerned about security you'll buy another server and NOT let your
users on the domain controller to begin with. If your users are truly
that savvy then why would you allow them on in the first place?

I'm sorry if this comes across the wrong way but I don't see how this is
MS"s fault in this case. there are legitimate reasons to allow users
access to the server drives.

And yes you can always directly edit the registry to hide the drives but
then you lose the capability to filter who gets hidden drives and who
doesn't.

Jeff Pitsch
Microsoft MVP - Terminal Services

S H A R I Q U E wrote:
[Quoted Text]
> I do Know about Group Policies to block access to certain Folder/Drives. Cant
> I use any other method to achieve the same.It is security breach and any
> technical user can play havoc with DC.I dont know it is default feature of
> Terminal Service to expose drive into open or not.If it yes, then it is
> colossal security flaw.what i mean there should be a prevention to local
> drive of TS server.
>
> regards
>
>
> "Jeff Pitsch" wrote:
>
>> You can use group policy to hide the server drives. Are you familiar
>> with group policy?
>>
>> Jeff Pitsch
>> Microsoft MVP - Terminal Services
>>
>> S H A R I Q U E wrote:
>>> Now, i am able to logon using domain users thanks to modifcation of local
>>> security policy.
>>> i have installed word viewer on WIN2K8 and provided access to WINXP client
>>> through TS RemoteApp Manager. I can run application at WINXP client
>>> successfully.
>>> one thing which is quite alarming is that after opening WordViewer at client
>>> side.When i goto File/Open, it gives domain user access to root of c driver
>>> and shows my local drive as network drive.
>>> How can i prevent users from accessing drives of WIN2K8 server.??
>>>
>>>
>>> "Jeff Pitsch" wrote:
>>>
>>>> Is the terminal server also a domain controller? If not, you need to
>>>> add the users to the Remote Desktop User group that is local to the
>>>> terminal server.
>>>>
>>>> Jeff Pitsch
>>>> Microsoft MVP - Terminal Services
>>>>
>>>> S H A R I Q U E wrote:
>>>>> I have created a Remote App programe in Windows Server 2008 TS.From Windows
>>>>> XP client having latest RDC 6.x installed, i can run the application
>>>>> successfully using Administrator account.When i try to run same application
>>>>> using domain use account, i get error that "To log on to this remote
>>>>> computer, you must be be granted the Allow log on through Terminal Services
>>>>> right. By default, members of the Remote Desktop Users group have this
>>>>> right...etc..."
>>>>>
>>>>> i have added the domain user/computer account in Remote Desktop uses group
>>>>> in AD even after that i am getting error.
>>>>> what piece of configuration I am missing.bear in mind that i am runnin this
>>>>> setup in VM with default number of TS licenses, that is, two.
Re: Windows Server 2008 TS Error.
"Vera Noest [MVP]" <vera.noest[ at ]remove-this.hem.utfors.se> 11/4/2008 10:33:04 PM
And keep in mind that *hiding* drives is merely a cosmetic thing,
it will still be fairly easy for users to get to those drives. The
only mechanism which truly disables access is NTFS permissions.
But as Jeff says, running TS on a DC is a disaster waiting to
happen...
_________________________________________________________
Vera Noest
MCSE, CCEA, Microsoft MVP - Terminal Server
TS troubleshooting: http://ts.veranoest.net
___ please respond in newsgroup, NOT by private email ___

Jeff Pitsch <jeff.pitsch.fake[ at ]jeffpitschconsulting.com> wrote on
04 nov 2008 in microsoft.public.windows.terminal_services:

[Quoted Text]
> It is a colossal security flaw to allow your users on the domain
> controller. It's not MS"s fault you've gone against best
> practices and decided to use your DC as a terminal server.
> there is a way to prevent users access to the local drives and
> that is through group policy. It is two settings you need to
> set and you are good to go. Is it perfect?
> Nope but it's the best we have right now. If you are truly,
> TRULY
> concerned about security you'll buy another server and NOT let
> your users on the domain controller to begin with. If your
> users are truly that savvy then why would you allow them on in
> the first place?
>
> I'm sorry if this comes across the wrong way but I don't see how
> this is MS"s fault in this case. there are legitimate reasons
> to allow users access to the server drives.
>
> And yes you can always directly edit the registry to hide the
> drives but then you lose the capability to filter who gets
> hidden drives and who doesn't.
>
> Jeff Pitsch
> Microsoft MVP - Terminal Services
>
> S H A R I Q U E wrote:
>> I do Know about Group Policies to block access to certain
>> Folder/Drives. Cant I use any other method to achieve the
>> same.It is security breach and any technical user can play
>> havoc with DC.I dont know it is default feature of Terminal
>> Service to expose drive into open or not.If it yes, then it is
>> colossal security flaw.what i mean there should be a prevention
>> to local drive of TS server.
>>
>> regards
>>
>>
>> "Jeff Pitsch" wrote:
>>
>>> You can use group policy to hide the server drives. Are you
>>> familiar with group policy?
>>>
>>> Jeff Pitsch
>>> Microsoft MVP - Terminal Services
>>>
>>> S H A R I Q U E wrote:
>>>> Now, i am able to logon using domain users thanks to
>>>> modifcation of local security policy.
>>>> i have installed word viewer on WIN2K8 and provided access
>>>> to WINXP client through TS RemoteApp Manager. I can run
>>>> application at WINXP client successfully.
>>>> one thing which is quite alarming is that after opening
>>>> WordViewer at client side.When i goto File/Open, it gives
>>>> domain user access to root of c driver and shows my local
>>>> drive as network drive. How can i prevent users from
>>>> accessing drives of WIN2K8 server.??
>>>>
>>>>
>>>> "Jeff Pitsch" wrote:
>>>>
>>>>> Is the terminal server also a domain controller? If not,
>>>>> you need to add the users to the Remote Desktop User group
>>>>> that is local to the terminal server.
>>>>>
>>>>> Jeff Pitsch
>>>>> Microsoft MVP - Terminal Services
>>>>>
>>>>> S H A R I Q U E wrote:
>>>>>> I have created a Remote App programe in Windows Server 2008
>>>>>> TS.From Windows XP client having latest RDC 6.x installed,
>>>>>> i can run the application successfully using Administrator
>>>>>> account.When i try to run same application using domain use
>>>>>> account, i get error that "To log on to this remote
>>>>>> computer, you must be be granted the Allow log on through
>>>>>> Terminal Services right. By default, members of the Remote
>>>>>> Desktop Users group have this right...etc..."
>>>>>>
>>>>>> i have added the domain user/computer account in Remote
>>>>>> Desktop uses group in AD even after that i am getting
>>>>>> error. what piece of configuration I am missing.bear in
>>>>>> mind that i am runnin this setup in VM with default number
>>>>>> of TS licenses, that is, two.
Re: Windows Server 2008 TS Error.
switch 12/28/2008 11:59:01 PM
I stumbled over exactly the same problem and I was unable to find resolve. My
conclusion: even when you a User Account, which is in the Domain User group,
is added to the Remote Desktop User group, this setup (a AD DC together with
TS on one box) refuses to have this type of User log in using Remote Desktop.

I am convinced now that the MS developers on purpose have chosen to built in
the security to have a User NOT to login when a TS and AD DC are running on
one box. Somehow the system checks if both TS and AD DC are on one box or not.

Pretty smart. However, why does MS sell WS Server 2008 with some 18 Server
Roles, knowing that they cannot be run on one box? I now know that TS, TS
License Server, DNS Server and AD DC all should be run on separate Hardware
Servers to make it secure. So, in fact one needs at least 5 hardware servers
(or can they be run on Virtual Servers?).

"Vera Noest [MVP]" wrote:

[Quoted Text]
> And keep in mind that *hiding* drives is merely a cosmetic thing,
> it will still be fairly easy for users to get to those drives. The
> only mechanism which truly disables access is NTFS permissions.
> But as Jeff says, running TS on a DC is a disaster waiting to
> happen...
> _________________________________________________________
> Vera Noest
> MCSE, CCEA, Microsoft MVP - Terminal Server
> TS troubleshooting: http://ts.veranoest.net
> ___ please respond in newsgroup, NOT by private email ___
>
> Jeff Pitsch <jeff.pitsch.fake[ at ]jeffpitschconsulting.com> wrote on
> 04 nov 2008 in microsoft.public.windows.terminal_services:
>
> > It is a colossal security flaw to allow your users on the domain
> > controller. It's not MS"s fault you've gone against best
> > practices and decided to use your DC as a terminal server.
> > there is a way to prevent users access to the local drives and
> > that is through group policy. It is two settings you need to
> > set and you are good to go. Is it perfect?
> > Nope but it's the best we have right now. If you are truly,
> > TRULY
> > concerned about security you'll buy another server and NOT let
> > your users on the domain controller to begin with. If your
> > users are truly that savvy then why would you allow them on in
> > the first place?
> >
> > I'm sorry if this comes across the wrong way but I don't see how
> > this is MS"s fault in this case. there are legitimate reasons
> > to allow users access to the server drives.
> >
> > And yes you can always directly edit the registry to hide the
> > drives but then you lose the capability to filter who gets
> > hidden drives and who doesn't.
> >
> > Jeff Pitsch
> > Microsoft MVP - Terminal Services
> >
> > S H A R I Q U E wrote:
> >> I do Know about Group Policies to block access to certain
> >> Folder/Drives. Cant I use any other method to achieve the
> >> same.It is security breach and any technical user can play
> >> havoc with DC.I dont know it is default feature of Terminal
> >> Service to expose drive into open or not.If it yes, then it is
> >> colossal security flaw.what i mean there should be a prevention
> >> to local drive of TS server.
> >>
> >> regards
> >>
> >>
> >> "Jeff Pitsch" wrote:
> >>
> >>> You can use group policy to hide the server drives. Are you
> >>> familiar with group policy?
> >>>
> >>> Jeff Pitsch
> >>> Microsoft MVP - Terminal Services
> >>>
> >>> S H A R I Q U E wrote:
> >>>> Now, i am able to logon using domain users thanks to
> >>>> modifcation of local security policy.
> >>>> i have installed word viewer on WIN2K8 and provided access
> >>>> to WINXP client through TS RemoteApp Manager. I can run
> >>>> application at WINXP client successfully.
> >>>> one thing which is quite alarming is that after opening
> >>>> WordViewer at client side.When i goto File/Open, it gives
> >>>> domain user access to root of c driver and shows my local
> >>>> drive as network drive. How can i prevent users from
> >>>> accessing drives of WIN2K8 server.??
> >>>>
> >>>>
> >>>> "Jeff Pitsch" wrote:
> >>>>
> >>>>> Is the terminal server also a domain controller? If not,
> >>>>> you need to add the users to the Remote Desktop User group
> >>>>> that is local to the terminal server.
> >>>>>
> >>>>> Jeff Pitsch
> >>>>> Microsoft MVP - Terminal Services
> >>>>>
> >>>>> S H A R I Q U E wrote:
> >>>>>> I have created a Remote App programe in Windows Server 2008
> >>>>>> TS.From Windows XP client having latest RDC 6.x installed,
> >>>>>> i can run the application successfully using Administrator
> >>>>>> account.When i try to run same application using domain use
> >>>>>> account, i get error that "To log on to this remote
> >>>>>> computer, you must be be granted the Allow log on through
> >>>>>> Terminal Services right. By default, members of the Remote
> >>>>>> Desktop Users group have this right...etc..."
> >>>>>>
> >>>>>> i have added the domain user/computer account in Remote
> >>>>>> Desktop uses group in AD even after that i am getting
> >>>>>> error. what piece of configuration I am missing.bear in
> >>>>>> mind that i am runnin this setup in VM with default number
> >>>>>> of TS licenses, that is, two.
>
Re: Windows Server 2008 TS Error.
"Vera Noest [MVP]" <vera.noest[ at ]remove-this.hem.utfors.se> 12/29/2008 1:47:03 PM
It's perfectly possible, but again: NOT recommended, to allow
normal domain users to connect to a combined DC / TS with the rdp
client. But you have to modify a setting in the Default Domain
Controller Security Policy:

Computer Configuration - Windows Settings - Security Settings -
Local Policies - User rights Assignment
"Allow log on through Terminal Services"

By default, this user right is granted to the Remote Desktop User
group on member servers, but only to Administrators on a DC. So
you have to give the Remote Desktop Users group this user right on
the DC.
And then you will have to modify the permissions on the rdp-tcp
connection properties as well.

You can safely run DC, DNS and TS Licensing Service on your DC
(assuming performance isn't a problem), only TS needs to run on a
separate server. Perfectly reasonable, since it's a multi-user
workstation.

_________________________________________________________
Vera Noest
MCSE, CCEA, Microsoft MVP - Terminal Server
TS troubleshooting: http://ts.veranoest.net
___ please respond in newsgroup, NOT by private email ___

=?Utf-8?B?c3dpdGNo?= <switch[ at ]discussions.microsoft.com> wrote on
29 dec 2008 in microsoft.public.windows.terminal_services:

[Quoted Text]
> I stumbled over exactly the same problem and I was unable to
> find resolve. My conclusion: even when you a User Account, which
> is in the Domain User group, is added to the Remote Desktop User
> group, this setup (a AD DC together with TS on one box) refuses
> to have this type of User log in using Remote Desktop.
>
> I am convinced now that the MS developers on purpose have chosen
> to built in the security to have a User NOT to login when a TS
> and AD DC are running on one box. Somehow the system checks if
> both TS and AD DC are on one box or not.
>
> Pretty smart. However, why does MS sell WS Server 2008 with some
> 18 Server Roles, knowing that they cannot be run on one box? I
> now know that TS, TS License Server, DNS Server and AD DC all
> should be run on separate Hardware Servers to make it secure.
> So, in fact one needs at least 5 hardware servers (or can they
> be run on Virtual Servers?).
>
> "Vera Noest [MVP]" wrote:
>
>> And keep in mind that *hiding* drives is merely a cosmetic
>> thing, it will still be fairly easy for users to get to those
>> drives. The only mechanism which truly disables access is NTFS
>> permissions. But as Jeff says, running TS on a DC is a disaster
>> waiting to happen...
>> _________________________________________________________
>> Vera Noest
>> MCSE, CCEA, Microsoft MVP - Terminal Server
>> TS troubleshooting: http://ts.veranoest.net
>> ___ please respond in newsgroup, NOT by private email ___
>>
>> Jeff Pitsch <jeff.pitsch.fake[ at ]jeffpitschconsulting.com> wrote
>> on 04 nov 2008 in microsoft.public.windows.terminal_services:
>>
>> > It is a colossal security flaw to allow your users on the
>> > domain controller. It's not MS"s fault you've gone against
>> > best practices and decided to use your DC as a terminal
>> > server. there is a way to prevent users access to the local
>> > drives and that is through group policy. It is two settings
>> > you need to set and you are good to go. Is it perfect?
>> > Nope but it's the best we have right now. If you are
>> > truly, TRULY
>> > concerned about security you'll buy another server and NOT
>> > let your users on the domain controller to begin with. If
>> > your users are truly that savvy then why would you allow them
>> > on in the first place?
>> >
>> > I'm sorry if this comes across the wrong way but I don't see
>> > how this is MS"s fault in this case. there are legitimate
>> > reasons to allow users access to the server drives.
>> >
>> > And yes you can always directly edit the registry to hide the
>> > drives but then you lose the capability to filter who gets
>> > hidden drives and who doesn't.
>> >
>> > Jeff Pitsch
>> > Microsoft MVP - Terminal Services
>> >
>> > S H A R I Q U E wrote:
>> >> I do Know about Group Policies to block access to certain
>> >> Folder/Drives. Cant I use any other method to achieve the
>> >> same.It is security breach and any technical user can play
>> >> havoc with DC.I dont know it is default feature of Terminal
>> >> Service to expose drive into open or not.If it yes, then it
>> >> is colossal security flaw.what i mean there should be a
>> >> prevention to local drive of TS server.
>> >>
>> >> regards
>> >>
>> >>
>> >> "Jeff Pitsch" wrote:
>> >>
>> >>> You can use group policy to hide the server drives. Are
>> >>> you familiar with group policy?
>> >>>
>> >>> Jeff Pitsch
>> >>> Microsoft MVP - Terminal Services
>> >>>
>> >>> S H A R I Q U E wrote:
>> >>>> Now, i am able to logon using domain users thanks to
>> >>>> modifcation of local security policy.
>> >>>> i have installed word viewer on WIN2K8 and provided
>> >>>> access to WINXP client through TS RemoteApp Manager. I can
>> >>>> run application at WINXP client successfully.
>> >>>> one thing which is quite alarming is that after opening
>> >>>> WordViewer at client side.When i goto File/Open, it gives
>> >>>> domain user access to root of c driver and shows my local
>> >>>> drive as network drive. How can i prevent users from
>> >>>> accessing drives of WIN2K8 server.??
>> >>>>
>> >>>>
>> >>>> "Jeff Pitsch" wrote:
>> >>>>
>> >>>>> Is the terminal server also a domain controller? If not,
>> >>>>> you need to add the users to the Remote Desktop User
>> >>>>> group that is local to the terminal server.
>> >>>>>
>> >>>>> Jeff Pitsch
>> >>>>> Microsoft MVP - Terminal Services
>> >>>>>
>> >>>>> S H A R I Q U E wrote:
>> >>>>>> I have created a Remote App programe in Windows Server
>> >>>>>> 2008 TS.From Windows XP client having latest RDC 6.x
>> >>>>>> installed, i can run the application successfully using
>> >>>>>> Administrator account.When i try to run same application
>> >>>>>> using domain use account, i get error that "To log on to
>> >>>>>> this remote computer, you must be be granted the Allow
>> >>>>>> log on through Terminal Services right. By default,
>> >>>>>> members of the Remote Desktop Users group have this
>> >>>>>> right...etc..."
>> >>>>>>
>> >>>>>> i have added the domain user/computer account in
>> >>>>>> Remote Desktop uses group in AD even after that i am
>> >>>>>> getting error. what piece of configuration I am
>> >>>>>> missing.bear in mind that i am runnin this setup in VM
>> >>>>>> with default number of TS licenses, that is, two.
"Allow log on through Terminal Services"
switch 12/29/2008 6:28:01 PM
Vera, thanks for your feedback. I found out this morning exactly the same
resolution you describe. However your explanation helped me to understand!
Thanks, very helpful.
Re: "Allow log on through Terminal Services"
"Vera Noest [MVP]" <vera.noest[ at ]remove-this.hem.utfors.se> 12/29/2008 8:48:16 PM
You're welcome, switch, and I'm glad that your problem is solved.
_________________________________________________________
Vera Noest
MCSE, CCEA, Microsoft MVP - Terminal Server
TS troubleshooting: http://ts.veranoest.net
___ please respond in newsgroup, NOT by private email ___

=?Utf-8?B?c3dpdGNo?= <switch[ at ]discussions.microsoft.com> wrote on
29 dec 2008 in microsoft.public.windows.terminal_services:

[Quoted Text]
> Vera, thanks for your feedback. I found out this morning exactly
> the same resolution you describe. However your explanation
> helped me to understand! Thanks, very helpful.
Re: Windows Server 2008 TS Error.
switch 12/30/2008 11:24:01 AM
Vera, could you please elaborate on how to disable access by using NTFS
permissions?

BTW, I was able to succesfully Allow log on thourgh Terminal Server right to
Domain Users. Would it be useful to the audience to publish all steps to
achieve? Let me know.

Cheers, switch

"Vera Noest [MVP]" wrote:

[Quoted Text]
> And keep in mind that *hiding* drives is merely a cosmetic thing,
> it will still be fairly easy for users to get to those drives. The
> only mechanism which truly disables access is NTFS permissions.
> But as Jeff says, running TS on a DC is a disaster waiting to
> happen...
> _________________________________________________________
> Vera Noest
> MCSE, CCEA, Microsoft MVP - Terminal Server
> TS troubleshooting: http://ts.veranoest.net
> ___ please respond in newsgroup, NOT by private email ___
>
> Jeff Pitsch <jeff.pitsch.fake[ at ]jeffpitschconsulting.com> wrote on
> 04 nov 2008 in microsoft.public.windows.terminal_services:
>
> > It is a colossal security flaw to allow your users on the domain
> > controller. It's not MS"s fault you've gone against best
> > practices and decided to use your DC as a terminal server.
> > there is a way to prevent users access to the local drives and
> > that is through group policy. It is two settings you need to
> > set and you are good to go. Is it perfect?
> > Nope but it's the best we have right now. If you are truly,
> > TRULY
> > concerned about security you'll buy another server and NOT let
> > your users on the domain controller to begin with. If your
> > users are truly that savvy then why would you allow them on in
> > the first place?
> >
> > I'm sorry if this comes across the wrong way but I don't see how
> > this is MS"s fault in this case. there are legitimate reasons
> > to allow users access to the server drives.
> >
> > And yes you can always directly edit the registry to hide the
> > drives but then you lose the capability to filter who gets
> > hidden drives and who doesn't.
> >
> > Jeff Pitsch
> > Microsoft MVP - Terminal Services
> >
> > S H A R I Q U E wrote:
> >> I do Know about Group Policies to block access to certain
> >> Folder/Drives. Cant I use any other method to achieve the
> >> same.It is security breach and any technical user can play
> >> havoc with DC.I dont know it is default feature of Terminal
> >> Service to expose drive into open or not.If it yes, then it is
> >> colossal security flaw.what i mean there should be a prevention
> >> to local drive of TS server.
> >>
> >> regards
> >>
> >>
> >> "Jeff Pitsch" wrote:
> >>
> >>> You can use group policy to hide the server drives. Are you
> >>> familiar with group policy?
> >>>
> >>> Jeff Pitsch
> >>> Microsoft MVP - Terminal Services
> >>>
> >>> S H A R I Q U E wrote:
> >>>> Now, i am able to logon using domain users thanks to
> >>>> modifcation of local security policy.
> >>>> i have installed word viewer on WIN2K8 and provided access
> >>>> to WINXP client through TS RemoteApp Manager. I can run
> >>>> application at WINXP client successfully.
> >>>> one thing which is quite alarming is that after opening
> >>>> WordViewer at client side.When i goto File/Open, it gives
> >>>> domain user access to root of c driver and shows my local
> >>>> drive as network drive. How can i prevent users from
> >>>> accessing drives of WIN2K8 server.??
> >>>>
> >>>>
> >>>> "Jeff Pitsch" wrote:
> >>>>
> >>>>> Is the terminal server also a domain controller? If not,
> >>>>> you need to add the users to the Remote Desktop User group
> >>>>> that is local to the terminal server.
> >>>>>
> >>>>> Jeff Pitsch
> >>>>> Microsoft MVP - Terminal Services
> >>>>>
> >>>>> S H A R I Q U E wrote:
> >>>>>> I have created a Remote App programe in Windows Server 2008
> >>>>>> TS.From Windows XP client having latest RDC 6.x installed,
> >>>>>> i can run the application successfully using Administrator
> >>>>>> account.When i try to run same application using domain use
> >>>>>> account, i get error that "To log on to this remote
> >>>>>> computer, you must be be granted the Allow log on through
> >>>>>> Terminal Services right. By default, members of the Remote
> >>>>>> Desktop Users group have this right...etc..."
> >>>>>>
> >>>>>> i have added the domain user/computer account in Remote
> >>>>>> Desktop uses group in AD even after that i am getting
> >>>>>> error. what piece of configuration I am missing.bear in
> >>>>>> mind that i am runnin this setup in VM with default number
> >>>>>> of TS licenses, that is, two.
>

Home | Search | Terms | Imprint Contact
Newsgroups Reader - provided by WiredBox.Net
Suche nach Orten, Städten, Postleitzahlen, Vorwahlen, Kfz-Kennzeichen