stm-tech Posted March 5, 2013 Posted March 5, 2013 Hi We have a couple of RDP servers to allow pupils to connect to the school network. The problem is one or two of them are adding the /admin switch to their command. Now whilst it would be great to just say "Don't do that" it will never work. Has anybody got any idea how I can say "if user is in group "pupils" and session="console" then delete?" I have had a look at - Re: Disable the console RDP session in Server 2003 but they seem to have a problem running it as a batch. How do others stop users logging in with the /admin or /console switch? Paul
PeterH Posted March 5, 2013 Posted March 5, 2013 Yep, you need to remove the Allow Logon Locally right from those users using either the local security policy on those servers or through group policy - Computer config | Policies | Windows Settings | Security Settings | Local Policies | User Rights Assignment | Allow log on locally PH
stm-tech Posted March 5, 2013 Author Posted March 5, 2013 Hi Peter Thanks for that, have set that up now. Paul
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now