PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Forums Hébergement > Forum Hébergement serveur > ms.win.server.setup > Prevent users from login into servers
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
Prevent users from login into servers

Réponse
 
LinkBack Outils de la discussion
Vieux 28/04/2008, 19h55   #1 (permalink)
Jordy
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Prevent users from login into servers

Hello

Is there a way to prevent users (not domain admins) from login into servers.
We have an enviroment were the servers are accessable to end users and I need
to prevent them from Login into the server directly, but still have access to
file and print when they login to workstation.

Thanks

  Réponse avec citation
Vieux 28/04/2008, 20h51   #2 (permalink)
Lanwench [MVP - Exchange]
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Prevent users from login into servers

Jordy <Jordy@discussions.microsoft.com> wrote:
> Hello
>
> Is there a way to prevent users (not domain admins) from login into
> servers. We have an enviroment were the servers are accessable to end
> users


You should have a locked cabinet or room, apart from everything else. If you
don't have physical security you don't have any security at all.

> and I need to prevent them from Login into the server directly,


End users should not be able to log into your servers now, either at the
console or via RD (unless this is a terminal server). Are they? If so,
perhaps they're members of groups they shouldn't be - or someone has been
monkeying around with policies.

> but still have access to file and print when they login to
> workstation.
>
> Thanks






  Réponse avec citation
Vieux 28/04/2008, 21h19   #3 (permalink)
Jordy
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Prevent users from login into servers

Ya I understand about the locked down part, but at the moment, that is not a
solution. It will be in the future....

But the end users still should not be able to login, and I don't understand
why. I have created a group policy that has restricted groups in it to all
all users to have local admin rights to there PC's (I know, a bad idea, but
needed at the moment).

They are able to login to any server, these are not DC's...

Thanks


"Lanwench [MVP - Exchange]" wrote:

> Jordy <Jordy@discussions.microsoft.com> wrote:
> > Hello
> >
> > Is there a way to prevent users (not domain admins) from login into
> > servers. We have an enviroment were the servers are accessable to end
> > users

>
> You should have a locked cabinet or room, apart from everything else. If you
> don't have physical security you don't have any security at all.
>
> > and I need to prevent them from Login into the server directly,

>
> End users should not be able to log into your servers now, either at the
> console or via RD (unless this is a terminal server). Are they? If so,
> perhaps they're members of groups they shouldn't be - or someone has been
> monkeying around with policies.
>
> > but still have access to file and print when they login to
> > workstation.
> >
> > Thanks

>
>
>
>
>
>

  Réponse avec citation
Vieux 29/04/2008, 05h34   #4 (permalink)
kj [SBS MVP]
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Prevent users from login into servers

Jordy wrote:
> Ya I understand about the locked down part, but at the moment, that
> is not a solution. It will be in the future....
>
> But the end users still should not be able to login, and I don't
> understand why. I have created a group policy that has restricted
> groups in it to all all users to have local admin rights to there
> PC's (I know, a bad idea, but needed at the moment).
>
> They are able to login to any server, these are not DC's...
>
> Thanks


Sounds like "users" (Domain Users?) have been granted the "logon locally
right" which is not by default. Because this sounds like multiple servers it
likely has been set in some group policy setting. Check one of your servers
to see if it has in fact been set, then you'll need to track down where.

>
>
> "Lanwench [MVP - Exchange]" wrote:
>
>> Jordy <Jordy@discussions.microsoft.com> wrote:
>>> Hello
>>>
>>> Is there a way to prevent users (not domain admins) from login into
>>> servers. We have an enviroment were the servers are accessable to
>>> end users

>>
>> You should have a locked cabinet or room, apart from everything
>> else. If you don't have physical security you don't have any
>> security at all.
>>
>>> and I need to prevent them from Login into the server directly,

>>
>> End users should not be able to log into your servers now, either at
>> the console or via RD (unless this is a terminal server). Are they?
>> If so, perhaps they're members of groups they shouldn't be - or
>> someone has been monkeying around with policies.
>>
>>> but still have access to file and print when they login to
>>> workstation.
>>>
>>> Thanks


--
/kj


  Réponse avec citation
Vieux 29/04/2008, 13h30   #5 (permalink)
Jordy
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Prevent users from login into servers

Hello

I looked at User rights, log on Locally. I have the group Administrators,
which I assume is a local group, in that local group, I have pushed down
Domain admins and Local Admins. Everyone is part of the local Admins, which I
assume explains the issue.

No the golden question, how do I get around that ?

Thanks

"kj [SBS MVP]" wrote:

> Jordy wrote:
> > Ya I understand about the locked down part, but at the moment, that
> > is not a solution. It will be in the future....
> >
> > But the end users still should not be able to login, and I don't
> > understand why. I have created a group policy that has restricted
> > groups in it to all all users to have local admin rights to there
> > PC's (I know, a bad idea, but needed at the moment).
> >
> > They are able to login to any server, these are not DC's...
> >
> > Thanks

>
> Sounds like "users" (Domain Users?) have been granted the "logon locally
> right" which is not by default. Because this sounds like multiple servers it
> likely has been set in some group policy setting. Check one of your servers
> to see if it has in fact been set, then you'll need to track down where.
>
> >
> >
> > "Lanwench [MVP - Exchange]" wrote:
> >
> >> Jordy <Jordy@discussions.microsoft.com> wrote:
> >>> Hello
> >>>
> >>> Is there a way to prevent users (not domain admins) from login into
> >>> servers. We have an enviroment were the servers are accessable to
> >>> end users
> >>
> >> You should have a locked cabinet or room, apart from everything
> >> else. If you don't have physical security you don't have any
> >> security at all.
> >>
> >>> and I need to prevent them from Login into the server directly,
> >>
> >> End users should not be able to log into your servers now, either at
> >> the console or via RD (unless this is a terminal server). Are they?
> >> If so, perhaps they're members of groups they shouldn't be - or
> >> someone has been monkeying around with policies.
> >>
> >>> but still have access to file and print when they login to
> >>> workstation.
> >>>
> >>> Thanks

>
> --
> /kj
>
>
>

  Réponse avec citation
Vieux 29/04/2008, 23h04   #6 (permalink)
kj [SBS MVP]
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Prevent users from login into servers

Jordy wrote:
> Hello
>
> I looked at User rights, log on Locally. I have the group
> Administrators, which I assume is a local group, in that local group,
> I have pushed down Domain admins and Local Admins. Everyone is part
> of the local Admins, which I assume explains the issue.
>
> No the golden question, how do I get around that ?


"everyone" group is a member of Local Adminstrators? That would do it.

Remove "Everyone" group from the "local adminstrators group " and track down
who made that 'decision'. I know someone with a two by four you can borrow
if needed.


>
> Thanks
>
> "kj [SBS MVP]" wrote:
>
>> Jordy wrote:
>>> Ya I understand about the locked down part, but at the moment, that
>>> is not a solution. It will be in the future....
>>>
>>> But the end users still should not be able to login, and I don't
>>> understand why. I have created a group policy that has restricted
>>> groups in it to all all users to have local admin rights to there
>>> PC's (I know, a bad idea, but needed at the moment).
>>>
>>> They are able to login to any server, these are not DC's...
>>>
>>> Thanks

>>
>> Sounds like "users" (Domain Users?) have been granted the "logon
>> locally right" which is not by default. Because this sounds like
>> multiple servers it likely has been set in some group policy
>> setting. Check one of your servers to see if it has in fact been
>> set, then you'll need to track down where.
>>
>>>
>>>
>>> "Lanwench [MVP - Exchange]" wrote:
>>>
>>>> Jordy <Jordy@discussions.microsoft.com> wrote:
>>>>> Hello
>>>>>
>>>>> Is there a way to prevent users (not domain admins) from login
>>>>> into servers. We have an enviroment were the servers are
>>>>> accessable to end users
>>>>
>>>> You should have a locked cabinet or room, apart from everything
>>>> else. If you don't have physical security you don't have any
>>>> security at all.
>>>>
>>>>> and I need to prevent them from Login into the server directly,
>>>>
>>>> End users should not be able to log into your servers now, either
>>>> at the console or via RD (unless this is a terminal server). Are
>>>> they? If so, perhaps they're members of groups they shouldn't be -
>>>> or someone has been monkeying around with policies.
>>>>
>>>>> but still have access to file and print when they login to
>>>>> workstation.
>>>>>
>>>>> Thanks

>>
>> --
>> /kj


--
/kj


  Réponse avec citation
Vieux 04/05/2008, 12h38   #7 (permalink)
Hank Arnold (MVP)
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Prevent users from login into servers

A 2x4 is being too gentle. "Tactical Nuclear Device" is what comes to
mind for me... ;-)

I'm *still* running into places 6 years later where "everyone" has
rights to certain resources. I change them to "Domain Users" at a minimum...

--

Regards,
Hank Arnold
Microsoft MVP
Windows Server - Directory Services

kj [SBS MVP] wrote:
> Jordy wrote:
>> Hello
>>
>> I looked at User rights, log on Locally. I have the group
>> Administrators, which I assume is a local group, in that local group,
>> I have pushed down Domain admins and Local Admins. Everyone is part
>> of the local Admins, which I assume explains the issue.
>>
>> No the golden question, how do I get around that ?

>
> "everyone" group is a member of Local Adminstrators? That would do it.
>
> Remove "Everyone" group from the "local adminstrators group " and track down
> who made that 'decision'. I know someone with a two by four you can borrow
> if needed.
>
>
>> Thanks
>>
>> "kj [SBS MVP]" wrote:
>>
>>> Jordy wrote:
>>>> Ya I understand about the locked down part, but at the moment, that
>>>> is not a solution. It will be in the future....
>>>>
>>>> But the end users still should not be able to login, and I don't
>>>> understand why. I have created a group policy that has restricted
>>>> groups in it to all all users to have local admin rights to there
>>>> PC's (I know, a bad idea, but needed at the moment).
>>>>
>>>> They are able to login to any server, these are not DC's...
>>>>
>>>> Thanks
>>> Sounds like "users" (Domain Users?) have been granted the "logon
>>> locally right" which is not by default. Because this sounds like
>>> multiple servers it likely has been set in some group policy
>>> setting. Check one of your servers to see if it has in fact been
>>> set, then you'll need to track down where.
>>>
>>>>
>>>> "Lanwench [MVP - Exchange]" wrote:
>>>>
>>>>> Jordy <Jordy@discussions.microsoft.com> wrote:
>>>>>> Hello
>>>>>>
>>>>>> Is there a way to prevent users (not domain admins) from login
>>>>>> into servers. We have an enviroment were the servers are
>>>>>> accessable to end users
>>>>> You should have a locked cabinet or room, apart from everything
>>>>> else. If you don't have physical security you don't have any
>>>>> security at all.
>>>>>
>>>>>> and I need to prevent them from Login into the server directly,
>>>>> End users should not be able to log into your servers now, either
>>>>> at the console or via RD (unless this is a terminal server). Are
>>>>> they? If so, perhaps they're members of groups they shouldn't be -
>>>>> or someone has been monkeying around with policies.
>>>>>
>>>>>> but still have access to file and print when they login to
>>>>>> workstation.
>>>>>>
>>>>>> Thanks
>>> --
>>> /kj

>

A 2x4 is being to gentle. Tactical Nuclear Device is what comes to mind
for me... ;-)

I'm still running into places 6 years later where "everyone" has rights
to resources. I change them to "Domain Users" at a minimum...

--

Regards,
Hank Arnold
Microsoft MVP
Windows Server - Directory Services
  Réponse avec citation
Vieux 05/05/2008, 05h47   #8 (permalink)
kj [SBS MVP]
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Prevent users from login into servers

Hank Arnold (MVP) wrote:
> A 2x4 is being too gentle. "Tactical Nuclear Device" is what comes to
> mind for me... ;-)


Quick and effective, but it's all over in a flash.

Excessive pain and suffering with the opportunity for multiple 'lessons' are
need here.

<g>

>
> I'm *still* running into places 6 years later where "everyone" has
> rights to certain resources. I change them to "Domain Users" at a
> minimum...
> --
>
> Regards,
> Hank Arnold
> Microsoft MVP
> Windows Server - Directory Services
>
> kj [SBS MVP] wrote:
>> Jordy wrote:
>>> Hello
>>>
>>> I looked at User rights, log on Locally. I have the group
>>> Administrators, which I assume is a local group, in that local
>>> group, I have pushed down Domain admins and Local Admins. Everyone
>>> is part of the local Admins, which I assume explains the issue.
>>>
>>> No the golden question, how do I get around that ?

>>
>> "everyone" group is a member of Local Adminstrators? That would do
>> it. Remove "Everyone" group from the "local adminstrators group " and
>> track down who made that 'decision'. I know someone with a two by
>> four you can borrow if needed.
>>
>>
>>> Thanks
>>>
>>> "kj [SBS MVP]" wrote:
>>>
>>>> Jordy wrote:
>>>>> Ya I understand about the locked down part, but at the moment,
>>>>> that is not a solution. It will be in the future....
>>>>>
>>>>> But the end users still should not be able to login, and I don't
>>>>> understand why. I have created a group policy that has restricted
>>>>> groups in it to all all users to have local admin rights to there
>>>>> PC's (I know, a bad idea, but needed at the moment).
>>>>>
>>>>> They are able to login to any server, these are not DC's...
>>>>>
>>>>> Thanks
>>>> Sounds like "users" (Domain Users?) have been granted the "logon
>>>> locally right" which is not by default. Because this sounds like
>>>> multiple servers it likely has been set in some group policy
>>>> setting. Check one of your servers to see if it has in fact been
>>>> set, then you'll need to track down where.
>>>>
>>>>>
>>>>> "Lanwench [MVP - Exchange]" wrote:
>>>>>
>>>>>> Jordy <Jordy@discussions.microsoft.com> wrote:
>>>>>>> Hello
>>>>>>>
>>>>>>> Is there a way to prevent users (not domain admins) from login
>>>>>>> into servers. We have an enviroment were the servers are
>>>>>>> accessable to end users
>>>>>> You should have a locked cabinet or room, apart from everything
>>>>>> else. If you don't have physical security you don't have any
>>>>>> security at all.
>>>>>>
>>>>>>> and I need to prevent them from Login into the server directly,
>>>>>> End users should not be able to log into your servers now, either
>>>>>> at the console or via RD (unless this is a terminal server). Are
>>>>>> they? If so, perhaps they're members of groups they shouldn't be
>>>>>> - or someone has been monkeying around with policies.
>>>>>>
>>>>>>> but still have access to file and print when they login to
>>>>>>> workstation.
>>>>>>>
>>>>>>> Thanks
>>>> --
>>>> /kj

>>

> A 2x4 is being to gentle. Tactical Nuclear Device is what comes to
> mind for me... ;-)
>
> I'm still running into places 6 years later where "everyone" has
> rights to resources. I change them to "Domain Users" at a minimum...


--
/kj


  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 16h12.


Édité par : vBulletin® version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,22581 seconds with 16 queries