Lock down RDS desktop.
have setup new windows 2012 rds environment , published-desktop group of users.
if want create gpo restrict users accessing critical system shortcuts such control panel, cmd, powershell, , lock down securities regular users, suggest link it?
our ad running on windows server 2008.
many thanks.
hi edkc,
there set of group policy settings have configure lock down rd session host server.
refer list below :
restricting device , resource redirection
restricting device , resource redirection can configured using following group policy parameter:
- computer configuration | policies | administrative templates | windows
-components | remote desktop services | session host remote desktop | redirection of device , resource
restricting printers redirection
restricting printers redirection can configured using following group policy parameter:
- computer configuration | policies | administrative templates | windows
components | remote desktop services | session host remote desktop | printer
redirection
restricting access control panel
restricting access control panel can configured using following group policy parameter:
- user configuration | policies | administrative templates | control panel
- parameter: deny access control panel , pc settings
restricting printer drivers installation
restricting printer drivers installation can configured using following group policy parameter:
- computer configuration | policies | windows settings | security settings |
-local policies | security options
- parameter : devices: prevent users installing printer drivers
restricting access registry
restricting access registry can configured using following group policy parameter:
- user configuration | policies | administrative templates | system
- parameter : prevent access registry editing tools
restricting access windows automatic updates
restricting access windows updates can configured using following group policy parameter:
- user configuration | policies | administrative templates | system
- parameter : windows automatic updates
restricting access start menu , network options
restriction access start menu , network options can configured using following group policy parameter:
- user configuration | policies | administrative templates | started menu ,
-taskbar
- parameter: disable settings match needs!
hide desktop icons
desktop icons can hidden using following group policy parameters:
- user configuration | policies | administrative templates | desktop
- parameters:
- hide , disable items on desktop
- delete "my computer" desktop
restricting access cd , floppy drive
restricting access cd , floppy can configured using following group policy parameters:
- computer configuration | policies | windows settings | security settings | local policies | security options
- parameters:
- devices: allow access cd-rom users locally logged on
- devices: allow floppy drive access local logged on user
restricting access command prompt
restricting access command prompt (cmd.exe) can configured using following group policy parameter:
- user configuration | policies | administrative templates | system
- parameter : disable access command prompt
restricting access task manager
restricting access task manager can configured using following group policy parameter:
- user configuration | policies | administrative templates | system | ctrl + alt + del options
- parameter:
- remove task manager
prevent users running unwanted applications
the goal prevent remote users running applications have not granted access.
preventing remote user running unwanted apps can configured using following group policy parameters:
- user configuration | policies | administrative templates | system
- parameters :
- do not run specified windows applications
- run specified windows applications
this extract of rds pocket consultant book
goodluck
hk.
hicham kadiri | guy
livre de référence rds 2012 r2 désormais disponible !
rds 2012 r2 reference book available !
découvrez tous mes ebooks )
Windows Server > Remote Desktop Services (Terminal Services)
Comments
Post a Comment