remote-desktop – 如何禁用Administrator的RDP访问权限

我们需要禁止域管理员帐户直接通过RDP访问服务器.我们的策略是以普通用户身份登录,然后使用“运行方式管理”功能.我们怎样设置它?

有问题的服务器正在运行带有远程桌面会话主机和基于会话的RD集合的Windows Server 2012 R2.允许的用户组不包含域管理员用户,但他仍能以某种方式登录.

谢谢.

这似乎是你在寻找:
http://support.microsoft.com/kb/2258492

To deny a user or a group logon via RDP,explicitly set the “Deny
logon through Remote Desktop Services” privilege. To do this access a
group policy editor (either local to the server or from a OU) and set
this privilege:

  1. Start | Run | Gpedit.msc if editing the local policy or chose the appropriate policy and edit it.

  2. Computer Configuration | Windows Settings | Security Settings | Local Policies | User Rights Assignment.

  3. Find and double click “Deny logon through Remote Desktop Services”

  4. Add the user and / or the group that you would like to dny access.

  5. Click ok.

  6. Either run gpupdate /force /target:computer or wait for the next policy refresh for this setting to take effect.

相关文章

文章浏览阅读2.2k次,点赞6次,收藏20次。在我们平时办公工作...
文章浏览阅读1k次。解决 Windows make command not found 和...
文章浏览阅读3.2k次,点赞2次,收藏6次。2、鼠标依次点击“计...
文章浏览阅读1.3w次。蓝光版属于高清版的一种。BD英文全名是...
文章浏览阅读974次,点赞7次,收藏8次。提供了更强大的功能,...
文章浏览阅读1.4w次,点赞5次,收藏22次。如果使用iterator的...