Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | User Access Control |
|---|---|
| Date: | Sat, 21 Jul 2007 13:31:05 -0700 |
Hello! We recently had to figure out how to use Group Policy to automate allowing groups of users to have Terminal Server access to different sets of hosts, either as a local user or local administrator. Not being a Windows Administrator of much experience, it took me a while to figure out all the knobs that needed tweaking.
The basic results are:
Computers go in an OU named after their role (say, "Webservers") Users go in two groups, "Webserver Users" and "Webserver Admins" Group Policy sets the local Remote Desktop Users and Administrator groups, along with the "Log on through Terminal Services" and "Log on through the Console" rights.
Once it's running, you pretty much just need to move the computer into the right part of the tree after joining the domain, and all the right access controls will cascade.
The process is documented here:
http://blog.hjksolutions.com/articles/2007/07/19/six-steps-to-automated-user-access-control-for-windows
I would love any feedback, or alternate ways to achieve the same net effect.
Thanks!
Adam
-- HJK Solutions - We Launch Startups - http://www.hjksolutions.com Adam Jacob, Senior Partner T: (206) 508-4759 E: adam@hjksolutions.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Windows XP End of Life., Jim Harrison |
|---|---|
| Next by Date: | RE: win2k3 active directory - firewall ports, Miha Pihler |
| Previous by Thread: | win2k3 active directory - firewall ports, dubaisans dubai |
| Next by Thread: | SecurityFocus Microsoft Newsletter #352, rkeith |
| Indexes: | [Date] [Thread] [Top] [All Lists] |