Subscribe to Windows IT Pro
December 17, 2002 12:00 AM

Access Denied: Protecting Workstations from Remote Access

Windows IT Pro
InstantDoc ID #27379
Rating: (0)

We want to make sure that no one can use Remote Assistance, Remote Desktop, or Windows 2000 Server Terminal Services to remotely access the workstations of certain users who have access to highly sensitive data or to financial transactions. What's the simplest way to disable all these features?

You can disable the Terminal Services service, which all the features you mentioned require. However, a user who's a member of the workstation's local Administrators group can reenable and start the service. To prevent that scenario, you can tighten Terminal Services' ACL, as I explained in "Auditing Users Who Might Be Starting and Stopping Services," May 2002, http://www.secadministrator.com, InstantDoc ID 24669. Alternatively, you can assign the Deny logon through Terminal Services right to the Everyone group. Assigning this right to Everyone overrides anyone who has the Allow logon through Terminal Services right.

However, for a more effective solution, I suggest you use an IP Security (IPSec) policy. For more information about how to use an IPSec policy, see "Protect Private Ports with IPSec," April 2002, http://www.secadministrator.com, InstantDoc ID 24273.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.