• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Second Remote Desktop group

Ahhzz

Moderator
Staff member
Joined
Feb 27, 2008
Messages
5,398 (1.31/day)
System Name Ironic
Processor Intel 2500k 4.4Ghz
Motherboard ASROCK|Z68 PROFESSIONAL Gen 3
Cooling Corsair H60
Memory 32GB GSkill Ripjaw X 1866
Video Card(s) Sapphire R9 290 Vapor-X 4Gb
Storage Western Digital Caviar Black 2TB SATA 3 (6G/s)
Display(s) 22" Dell Wide/ 22" Acer wide/24" Asus
Case Antec Lanboy Air Black & Blue
Audio Device(s) SB Audigy 7.1
Power Supply Corsair Enthusiast TX750
Mouse Logitech G9x, custom frame
Keyboard Corsair Vengeance K95
Software Win 7 Ult 64 bit
We don't have a specific Server thread, so I decided RDP is a network process, therefore, Network thread :)

So, I've got an RDP/TS server I manage, and on rare occasion, one of the software packages installed needs maintenance, and the supporting group is a 9 to 4 type group. During maintenance, I need all the "normal" users to stay off, while allowing the support group and admin groups access. Unfortunately, Windows server OS does not have an easy method to disable all but a few RDP users at once, much less re-enable them. Does anyone know if there's a way to "Copy" the RDP group to a second group , and use that as a "common users" which I can disable and enable easily? Thanks!

edit for a little more detail
 
Last edited:

Solaris17

Dainty Moderator
Staff member
Joined
Aug 16, 2005
Messages
20,526 (4.06/day)
Location
Florida
System Name Venslar
Processor I9 7980XE
Motherboard MSI x299 Tomahawk Arctic
Cooling EK Custom
Memory 32GB Corsair DDR4 3000mhz
Video Card(s) Nvidia Titan RTX
Storage 2x 2TB Micron SSDs | 1x ADATA 128SSD | 1x Drevo 256SSD | 1x 1TB 850 EVO | 1x 250GB 960 EVO
Display(s) 3x AOC Q2577PWQ (2k IPS)
Case Inwin 303 White (Thermaltake Ring 120mm Purple accent)
Audio Device(s) Realtek ALC 1220 on Audio-Technica ATH-AG1
Power Supply Seasonic 1050W Snow
Mouse Roccat Tyon White
Keyboard Ducky Shine 6 Snow White
Software Windows 10 x64 Pro
You can make 2 GPOs. One that has the OU of the support staff and one that Denies RDP access to the users. Whenever you need to do maint, just make it a req that users need to leave systems or w/e on and then enable the GPO restricting the user OU and enable the OU for the support OU. then force a GP update via GPEDIT to those systems.

At the end of maint, just disable both (since your default policy allows it for all users it seems) and force GPU update to all systems again and reboot them remotely.
 

Ahhzz

Moderator
Staff member
Joined
Feb 27, 2008
Messages
5,398 (1.31/day)
System Name Ironic
Processor Intel 2500k 4.4Ghz
Motherboard ASROCK|Z68 PROFESSIONAL Gen 3
Cooling Corsair H60
Memory 32GB GSkill Ripjaw X 1866
Video Card(s) Sapphire R9 290 Vapor-X 4Gb
Storage Western Digital Caviar Black 2TB SATA 3 (6G/s)
Display(s) 22" Dell Wide/ 22" Acer wide/24" Asus
Case Antec Lanboy Air Black & Blue
Audio Device(s) SB Audigy 7.1
Power Supply Corsair Enthusiast TX750
Mouse Logitech G9x, custom frame
Keyboard Corsair Vengeance K95
Software Win 7 Ult 64 bit
You can make 2 GPOs. One that has the OU of the support staff and one that Denies RDP access to the users. Whenever you need to do maint, just make it a req that users need to leave systems or w/e on and then enable the GPO restricting the user OU and enable the OU for the support OU. then force a GP update via GPEDIT to those systems.

At the end of maint, just disable both (since your default policy allows it for all users it seems) and force GPU update to all systems again and reboot them remotely.
Not a bad idea, may give that a whirl, thanks :)
 

Solaris17

Dainty Moderator
Staff member
Joined
Aug 16, 2005
Messages
20,526 (4.06/day)
Location
Florida
System Name Venslar
Processor I9 7980XE
Motherboard MSI x299 Tomahawk Arctic
Cooling EK Custom
Memory 32GB Corsair DDR4 3000mhz
Video Card(s) Nvidia Titan RTX
Storage 2x 2TB Micron SSDs | 1x ADATA 128SSD | 1x Drevo 256SSD | 1x 1TB 850 EVO | 1x 250GB 960 EVO
Display(s) 3x AOC Q2577PWQ (2k IPS)
Case Inwin 303 White (Thermaltake Ring 120mm Purple accent)
Audio Device(s) Realtek ALC 1220 on Audio-Technica ATH-AG1
Power Supply Seasonic 1050W Snow
Mouse Roccat Tyon White
Keyboard Ducky Shine 6 Snow White
Software Windows 10 x64 Pro
I only reccomend it because I use similar restrictions. By default I dont want techs attempting to RDP into my servers, but I do want them to be able to RDP into the LAB environment for extended learning. Likewise I do NOT want the POS PCs to be able to RDP at all. So I have GPO restrictions preventing this kind of stuff.
 
Top