Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Microsoft
[Top] [All Lists]

User Access Control

Subject: User Access Control
Date: Sat, 21 Jul 2007 13:31:05 -0700
Hello!  We recently had to figure out how to use Group Policy to
automate allowing groups of users to have Terminal Server access to
different sets of hosts, either as a local user or local
administrator.  Not being a Windows Administrator of much experience,
it took me a while to figure out all the knobs that needed tweaking.

The basic results are:

Computers go in an OU named after their role (say, "Webservers")
Users go in two groups, "Webserver Users" and "Webserver Admins"
Group Policy sets the local Remote Desktop Users and Administrator
groups, along with the "Log on through Terminal Services" and "Log on
through the Console" rights.

Once it's running, you pretty much just need to move the computer into
the right part of the tree after joining the domain, and all the right
access controls will cascade.

The process is documented here:

http://blog.hjksolutions.com/articles/2007/07/19/six-steps-to-automated-user-access-control-for-windows

I would love any feedback, or alternate ways to achieve the same net effect.

Thanks!

Adam

--
HJK Solutions - We Launch Startups - http://www.hjksolutions.com
Adam Jacob, Senior Partner
T: (206) 508-4759 E: adam@hjksolutions.com

<Prev in Thread] Current Thread [Next in Thread>
  • User Access Control, Adam Jacob <=