Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > how can I limit ts local user on a stand alone server?

Reply
Thread Tools Display Modes

how can I limit ts local user on a stand alone server?

 
 
alex
Guest
Posts: n/a

 
      04-27-2009
I have a 2003 srv stand alone (not domain), I need to limit some teminal
server user, for exmple not shut down, remove items from start menu and
other things that are easy to do with gpo and domain.
I've tryed to modify the local policy, section user, but the the policy are
applyed to ALL users, included administrator.
How can I make a local policy and have it appied only to some users?
Thank you
Alex


 
Reply With Quote
 
 
 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      04-27-2009
Hello Alex,

You can edit for some security settings the "Local security policy", Local
policies, User rights assignment:
"Shut down the system"

Additional have a look at this article:
http://support.microsoft.com/kb/325351

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> I have a 2003 srv stand alone (not domain), I need to limit some
> teminal
> server user, for exmple not shut down, remove items from start menu
> and
> other things that are easy to do with gpo and domain.
> I've tryed to modify the local policy, section user, but the the
> policy are
> applyed to ALL users, included administrator.
> How can I make a local policy and have it appied only to some users?
> Thank you
> Alex



 
Reply With Quote
 
alex
Guest
Posts: n/a

 
      04-27-2009
yes but then the policy apply to all users, included administrator!!

"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> ha scritto nel messaggio
news: .com...
> Hello Alex,
>
> You can edit for some security settings the "Local security policy", Local
> policies, User rights assignment:
> "Shut down the system"
>
> Additional have a look at this article:
> http://support.microsoft.com/kb/325351
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> I have a 2003 srv stand alone (not domain), I need to limit some
>> teminal
>> server user, for exmple not shut down, remove items from start menu
>> and
>> other things that are easy to do with gpo and domain.
>> I've tryed to modify the local policy, section user, but the the
>> policy are
>> applyed to ALL users, included administrator.
>> How can I make a local policy and have it appied only to some users?
>> Thank you
>> Alex

>
>



 
Reply With Quote
 
alex
Guest
Posts: n/a

 
      04-27-2009
sorry, I've read just now the article... Thank you!
"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> ha scritto nel messaggio
news: .com...
> Hello Alex,
>
> You can edit for some security settings the "Local security policy", Local
> policies, User rights assignment:
> "Shut down the system"
>
> Additional have a look at this article:
> http://support.microsoft.com/kb/325351
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> I have a 2003 srv stand alone (not domain), I need to limit some
>> teminal
>> server user, for exmple not shut down, remove items from start menu
>> and
>> other things that are easy to do with gpo and domain.
>> I've tryed to modify the local policy, section user, but the the
>> policy are
>> applyed to ALL users, included administrator.
>> How can I make a local policy and have it appied only to some users?
>> Thank you
>> Alex

>
>



 
Reply With Quote
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      04-27-2009
Hello Alex,

For the "shut down the system" setting you add the groups that are allowed
to do it. So you can only use the administrators group. For the rest you
have the article as you saw.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> yes but then the policy apply to all users, included administrator!!
>
> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> ha scritto nel
> messaggio news: .com...
>
>> Hello Alex,
>>
>> You can edit for some security settings the "Local security policy",
>> Local
>> policies, User rights assignment:
>> "Shut down the system"
>> Additional have a look at this article:
>> http://support.microsoft.com/kb/325351
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> I have a 2003 srv stand alone (not domain), I need to limit some
>>> teminal
>>> server user, for exmple not shut down, remove items from start menu
>>> and
>>> other things that are easy to do with gpo and domain.
>>> I've tryed to modify the local policy, section user, but the the
>>> policy are
>>> applyed to ALL users, included administrator.
>>> How can I make a local policy and have it appied only to some users?
>>> Thank you
>>> Alex



 
Reply With Quote
 
alex
Guest
Posts: n/a

 
      04-27-2009
I've tryed with the article, but if administrator run gpupdate / force the
policy are reapplyed also to administrator.

"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> ha scritto nel messaggio
news: .com...
> Hello Alex,
>
> For the "shut down the system" setting you add the groups that are allowed
> to do it. So you can only use the administrators group. For the rest you
> have the article as you saw.
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> yes but then the policy apply to all users, included administrator!!
>>
>> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> ha scritto nel
>> messaggio news: .com...
>>
>>> Hello Alex,
>>>
>>> You can edit for some security settings the "Local security policy",
>>> Local
>>> policies, User rights assignment:
>>> "Shut down the system"
>>> Additional have a look at this article:
>>> http://support.microsoft.com/kb/325351
>>> Best regards
>>>
>>> Meinolf Weber
>>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>>> confers no rights.
>>> ** Please do NOT email, only reply to Newsgroups
>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>> I have a 2003 srv stand alone (not domain), I need to limit some
>>>> teminal
>>>> server user, for exmple not shut down, remove items from start menu
>>>> and
>>>> other things that are easy to do with gpo and domain.
>>>> I've tryed to modify the local policy, section user, but the the
>>>> policy are
>>>> applyed to ALL users, included administrator.
>>>> How can I make a local policy and have it appied only to some users?
>>>> Thank you
>>>> Alex

>
>



 
Reply With Quote
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      04-27-2009
Hello Alex,

If you follow the steps in the article there is no need to run gpupdate command.
The machine is a workgroup machine and not only disconnected from a domain?

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> I've tryed with the article, but if administrator run gpupdate / force
> the policy are reapplyed also to administrator.
>
> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> ha scritto nel
> messaggio news: .com...
>
>> Hello Alex,
>>
>> For the "shut down the system" setting you add the groups that are
>> allowed to do it. So you can only use the administrators group. For
>> the rest you have the article as you saw.
>>
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> yes but then the policy apply to all users, included administrator!!
>>>
>>> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> ha scritto nel
>>> messaggio news: .com...
>>>
>>>> Hello Alex,
>>>>
>>>> You can edit for some security settings the "Local security
>>>> policy",
>>>> Local
>>>> policies, User rights assignment:
>>>> "Shut down the system"
>>>> Additional have a look at this article:
>>>> http://support.microsoft.com/kb/325351
>>>> Best regards
>>>> Meinolf Weber
>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>> and
>>>> confers no rights.
>>>> ** Please do NOT email, only reply to Newsgroups
>>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>> I have a 2003 srv stand alone (not domain), I need to limit some
>>>>> teminal
>>>>> server user, for exmple not shut down, remove items from start
>>>>> menu
>>>>> and
>>>>> other things that are easy to do with gpo and domain.
>>>>> I've tryed to modify the local policy, section user, but the the
>>>>> policy are
>>>>> applyed to ALL users, included administrator.
>>>>> How can I make a local policy and have it appied only to some
>>>>> users?
>>>>> Thank you
>>>>> Alex



 
Reply With Quote
 
alex
Guest
Posts: n/a

 
      04-27-2009
it's a workgroup server. I follow the article and it works fine, but if
somebody runs gpupdate the stict policy is reapplyed to administrator. In
this case administrator will loose his role...
Maybe I can try to deny administrator read permission on registry.pol ...

"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> ha scritto nel messaggio
news: .com...
> Hello Alex,
>
> If you follow the steps in the article there is no need to run gpupdate
> command. The machine is a workgroup machine and not only disconnected from
> a domain?
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> I've tryed with the article, but if administrator run gpupdate / force
>> the policy are reapplyed also to administrator.
>>
>> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> ha scritto nel
>> messaggio news: .com...
>>
>>> Hello Alex,
>>>
>>> For the "shut down the system" setting you add the groups that are
>>> allowed to do it. So you can only use the administrators group. For
>>> the rest you have the article as you saw.
>>>
>>> Best regards
>>>
>>> Meinolf Weber
>>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>>> confers no rights.
>>> ** Please do NOT email, only reply to Newsgroups
>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>> yes but then the policy apply to all users, included administrator!!
>>>>
>>>> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> ha scritto nel
>>>> messaggio news: .com...
>>>>
>>>>> Hello Alex,
>>>>>
>>>>> You can edit for some security settings the "Local security
>>>>> policy",
>>>>> Local
>>>>> policies, User rights assignment:
>>>>> "Shut down the system"
>>>>> Additional have a look at this article:
>>>>> http://support.microsoft.com/kb/325351
>>>>> Best regards
>>>>> Meinolf Weber
>>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>>> and
>>>>> confers no rights.
>>>>> ** Please do NOT email, only reply to Newsgroups
>>>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>>> I have a 2003 srv stand alone (not domain), I need to limit some
>>>>>> teminal
>>>>>> server user, for exmple not shut down, remove items from start
>>>>>> menu
>>>>>> and
>>>>>> other things that are easy to do with gpo and domain.
>>>>>> I've tryed to modify the local policy, section user, but the the
>>>>>> policy are
>>>>>> applyed to ALL users, included administrator.
>>>>>> How can I make a local policy and have it appied only to some
>>>>>> users?
>>>>>> Thank you
>>>>>> Alex

>
>



 
Reply With Quote
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      04-28-2009
Hello Alex,

Reconfigure gpupdate.exe permissions for administrators only. I can not test
it in the moment. Maybe i will find later on some time.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> it's a workgroup server. I follow the article and it works fine, but
> if
> somebody runs gpupdate the stict policy is reapplyed to administrator.
> In
> this case administrator will loose his role...
> Maybe I can try to deny administrator read permission on registry.pol
> ...
> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> ha scritto nel
> messaggio news: .com...
>
>> Hello Alex,
>>
>> If you follow the steps in the article there is no need to run
>> gpupdate command. The machine is a workgroup machine and not only
>> disconnected from a domain?
>>
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> I've tryed with the article, but if administrator run gpupdate /
>>> force the policy are reapplyed also to administrator.
>>>
>>> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> ha scritto nel
>>> messaggio news: .com...
>>>
>>>> Hello Alex,
>>>>
>>>> For the "shut down the system" setting you add the groups that are
>>>> allowed to do it. So you can only use the administrators group. For
>>>> the rest you have the article as you saw.
>>>>
>>>> Best regards
>>>>
>>>> Meinolf Weber
>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>> and
>>>> confers no rights.
>>>> ** Please do NOT email, only reply to Newsgroups
>>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>> yes but then the policy apply to all users, included
>>>>> administrator!!
>>>>>
>>>>> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> ha scritto nel
>>>>> messaggio
>>>>> news: .com...
>>>>>
>>>>>> Hello Alex,
>>>>>>
>>>>>> You can edit for some security settings the "Local security
>>>>>> policy",
>>>>>> Local
>>>>>> policies, User rights assignment:
>>>>>> "Shut down the system"
>>>>>> Additional have a look at this article:
>>>>>> http://support.microsoft.com/kb/325351
>>>>>> Best regards
>>>>>> Meinolf Weber
>>>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>>>> and
>>>>>> confers no rights.
>>>>>> ** Please do NOT email, only reply to Newsgroups
>>>>>> ** HELP us help YOU!!!
>>>>>> http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>>>> I have a 2003 srv stand alone (not domain), I need to limit some
>>>>>>> teminal
>>>>>>> server user, for exmple not shut down, remove items from start
>>>>>>> menu
>>>>>>> and
>>>>>>> other things that are easy to do with gpo and domain.
>>>>>>> I've tryed to modify the local policy, section user, but the the
>>>>>>> policy are
>>>>>>> applyed to ALL users, included administrator.
>>>>>>> How can I make a local policy and have it appied only to some
>>>>>>> users?
>>>>>>> Thank you
>>>>>>> Alex



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Limit user logon time in a domain Windows Server 2003 script Gustavo Scripting 6 11-29-2007 12:01 AM
Exchange server user mailbox limit H Edelman Windows Small Business Server 4 08-20-2007 11:16 AM
Domain user credentials seen as local user on member server sysadmin guy Active Directory 0 06-21-2006 04:33 PM
limit user domain connections on 2003 server paul Burchell Windows Server 1 09-09-2004 08:47 PM
Add a user to a stand alone server Oded Tal Scripting 3 07-26-2004 07:07 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59