Recommended Posts

Dear All,

We've recently installed Terminal Services Licensing on our Domain controller and the Terminal Service on to another server as application mode in order to login to it using specific users from our active directory to access an Application.

The Problem:

Any user from our active directory is able to login to that server

Requirement:

Only Specific users or Groups (OU) must login to that server.

Solution Found:

At each user level in the active directory there is a tab called (Terminal Services Profile) in which allow logon to terminal server is Checked? by un-checking it the user will not be able to login to that server.

BUT!!! Doing this excessive for 400+ users is headache..

Can anyone guide me in how to achieve this task in which ever way?

I'm very new to Terminal Services

I hope my explanation is clear... incase of any questions i'll be back to the net after an hour and a half

regards... and thanks alot to all of you

post-71571-1116390843.jpg

Link to comment
https://www.neowin.net/forum/topic/321782-terminal-services/
Share on other sites

Can you separate them into 2 different groups and then assign one group the ability to log on and the other not?

585937090[/snapback]

Thats what I was thinking but it's kind of dirty. You also will probably want to make 2 new under your OIB.

My knowledge is limited on AD, GP but I'm trying to learn.

In order to log onto the TS server, you have to have the logon locally permission. Chances are, you assigned that permissionto the Domain Users Group in order to get things working. Change that to include an new OU called TSusers and remove domain users, then add just the users to that group.

Btw, Domain Users may be a part of a local group that is allowed the log-on-locally permission, so you may have to hunt.

Edited by Billprozac
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • These features described above are good, but far from what developers like me was eager to get. And that main feature that developers will love it`s the ability to connect to LOCAL AI models running on Ollama. So if you have a beefy spec machine you can now use your own model 100% local inside Visual Studio 2026 18.7.0
    • Microsoft Teams is getting a controversial location tracking feature that users may hate by Usama Jawad Image generated with Microsoft Copilot Earlier this year, Microsoft planned to roll out a controversial location tracking feature in Teams, but following customer feedback, it decided to delay its release. The bad news is that the company has decided to launch it later this year, but it's based on roughly the same design that was shared earlier, which means that many users still have good reason to worry. Basically, Microsoft Places and Teams have received workplace check-ins via Wi-Fi. The idea is that if an employee arrives at the office and connects to their enterprise network, their profile status indicator will show them as being present in the office. For example, if you arrive at work, open Teams on your PC, and connect to the "Studio B" company Wi-Fi network, your Teams profile will indicate that you are present in "Studio B", as shown below: Microsoft says that this feature is basically a replacement for physical workplace check-in peripherals, it reduces the need to manually update your status, and it also enables co-workers to know that you're at work so that they can coordinate in-person meetings with you. IT admins can enable this workplace check-in capability at a tenant level, and users have the ability to control whether they want to enable it or not. Of course, all of that sounds great on paper, but naturally, many Teams customers may still have concerns, as they did before. This is because it enables your reporting manager and other members of the organization to track if you are at the office, when you arrive at the office, and where you are right now. This could be problematic for people who work in what they consider to be flexible work environments or hybrid setups, and this kind of location tracking could be considered an invasion of privacy. Microsoft has tried to alleviate some of these concerns by letting users know that they can manually set their location easily, which essentially overrides workplace check-in if they feel uncomfortable with it. However, that doesn't really solve the problem because your organization could enforce a workplace policy that mandates that this feature remains enabled. The Redmond tech giant has also assured users that this capability does not store historical data and is only a real-time indicator of location. Finally, it only generates a signal when you connect to a corporate network, which means that if you are working from home and connect your PC to your personal Wi-Fi, it won't broadcast your location to your employer; you will simply be shown as "Remote". Microsoft has encouraged IT admins to prepare for this change and begin informing users so they know what to expect once it begins rolling out later this year.
    • Wow, Microsoft IS cooking lately... This only shows that they COULD improve, they just chose not to for whatever reasons. That obsession with AI was destroying them from the inside out.
  • Recent Achievements

    • Very Popular
      AndrewSteel earned a badge
      Very Popular
    • Veteran
      Taliseian went up a rank
      Veteran
    • One Month Later
      Clizby earned a badge
      One Month Later
    • One Month Later
      Timaximus earned a badge
      One Month Later
    • Week One Done
      Timaximus earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      511
    2. 2
      +Edouard
      162
    3. 3
      PsYcHoKiLLa
      157
    4. 4
      Steven P.
      83
    5. 5
      ATLien_0
      80
  • Tell a friend

    Love Neowin? Tell a friend!