RDS users can do everything on server


hi there,

i have build new server environment client of mine, have build following servers following roles:

dc server (ad/dns/dhcp/rd licencing)
rras (connection broker/gateway/rd web access)
rds(session host)
sql (sql server)

the problem users login on rds can everything, install/remove software, start computer management, start cmd etc.

so have admin privileges, not in admin group! have looked simple gpo can block these admin privileges without luck.

what can , how can fixed?

kind regards,


mazen abdelaal

sounds logon administrators, larger problem mixing these roles on 1 server instance. active directory domain controller should not have other roles rras, rds, sql installed on it. individual roles configuration collide , cause unexpected results.

https://support.microsoft.com/en-us/kb/2032911

https://support.microsoft.com/en-us/kb/292822

to issue rds configuration can add them here rather make them administrators, again there's conflicts encountered.

https://technet.microsoft.com/en-us/library/cc743161%28v=ws.11%29.aspx?f=255&mspperror=-2147217396

also ask here specific rds questions.

https://social.technet.microsoft.com/forums/windowsserver/en-us/home?forum=winserverts

 

 



regards, dave patrick ....
microsoft certified professional
microsoft mvp [windows server] datacenter management

disclaimer: posting provided "as is" no warranties or guarantees, , confers no rights.



Windows Server  >  Windows Server 2012 General



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file