PC Review Forums Newsgroups Windows 2000 Microsoft Windows 2000 Terminal Server Applications Terminal Service on Domain Controller?

Reply

Terminal Service on Domain Controller?

 
Thread Tools Rate Thread
Old 14-01-2004, 05:32 PM   #1
John Smith
Guest
 
Posts: n/a
Default Terminal Service on Domain Controller?


Should Terminal Service be installed on a DC?

Also, How do I prevent users from accesing other
applications on the Server?

Thanks
  Reply With Quote
Old 14-01-2004, 06:16 PM   #2
Ivan Leichtling [MSFT]
Guest
 
Posts: n/a
Default Re: Terminal Service on Domain Controller?

The Terminal Services FAQ
http://www.microsoft.com/windows200...rminal_faq.mspx
is a great place to get answers to both these questions:

Q. I want to deploy Terminal Server on my domain controller. How do I
give users access?

A. While Microsoft does not recommend this practice, as it compromises
security on the domain controller, you can find information in Domain
Controllers Require the "Log on Locally" Group Policy Object for
Terminal Services Client Connections (Q247989)
http://support.microsoft.com/defaul...b;en-us;q247989 in the
Microsoft Knowledge Base.


Q. How do I "lock down" my terminal server?

A. For Windows 2000 Server, see David Mackey's Securing Windows 2000
Terminal Services white paper.
http://www.microsoft.com/technet/tr...ze/secw2kts.asp

For Windows Server 2003 and Windows XP, you can restrict what software
users can run on the server. See Using Software Restriction Policies
to Protect Against Unauthorized Software
http://www.microsoft.com/windowsxp/...ictionpolicies/
and Locking Down Windows Server 2003 Terminal Server Sessions
http://www.microsoft.com/downloads/...&DisplayLang=en


On Wed, 14 Jan 2004 09:32:07 -0800, "John Smith"
<anonymous@discussions.microsoft.com> wrote:

>Should Terminal Service be installed on a DC?
>
>Also, How do I prevent users from accesing other
>applications on the Server?
>
>Thanks


This posting is provided "AS IS" with no warranties, and confers no rights
  Reply With Quote
Old 14-01-2004, 10:10 PM   #3
paul
Guest
 
Posts: n/a
Default Terminal Service on Domain Controller?

In general it is easier to secure servers if you segregate
their roles. You should see the better reliability from
your servers, and easier troubleshooting as well.
Terminal servers require a fair amount of administration
in the form of application updates, reboots, etc.
Generally I try to keep my domain controllers up except
for application of service packs and hotfixes. However,
if your needs dictate it, it is possible to run a DC as a
terminal server.

As for access to other applications there are many
different ways to restrict access to applications.
Modification of permissions, using Citrix to publish
applications, or THOR from http://www.tricerat.com/ are
just a few.

Paul

  Reply With Quote
Old 15-01-2004, 03:01 AM   #4
Mark Mancini
Guest
 
Posts: n/a
Default Re: Terminal Service on Domain Controller?

reality, small companies cannot afford a 2nd server for remote access just
to appease best practices. It should be secured well. I designed and use
AppLauncher for locking down access to apps and it is used by hospitals,
banks, resorts, and Burger King. Much cheaper alternative to Citrix which
is what I used to sell.

--
Sincerely,
Mark Mancini, CCA, CCNA, Master CIW&CI, CNE 4&5, MCSE+I 4&2000
www.MCSE2000.com
www.AppLauncher.com



"John Smith" <anonymous@discussions.microsoft.com> wrote in message
news:027301c3dac4$554a1730$a101280a@phx.gbl...
> Should Terminal Service be installed on a DC?
>
> Also, How do I prevent users from accesing other
> applications on the Server?
>
> Thanks



  Reply With Quote
Reply



Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off