Windows Server 2008 R2 > Restrict Session Stealing for Generic Accounts when session is Active


in rdsh server farm have accounts generic (assigned thin client stations).  each station has windows account associated station.  rdsh farm allows single session per user account not have hundreds of sessions same username.  thin client's rdp connection not store credentials user "expected" logon username listed on monitor.  imagine, users have own inclinations.

we wanting ensure active session can not stolen user @ different station.  if session disconnected, allow reconnection client.  idea seems simple enough i'd think basic security microsoft remote desktop session hosting.

windows server 2003 terminal services had functionality similar with:
http://technet.microsoft.com/en-us/library/cc759021(v=ws.10).aspx
group policy > computer configuration > administrative templates > windows components > terminal services > sessions > allow reconnection original client only

i surprised find microsoft dropped feature in windows server 2008, , more surprised there apparently no "local security policy" - "user rights assignment" seem control functionality.

does know of way enforce such security policy prevent session stealing such this?

the closest i've found situation is: http://forums.citrix.com/thread.jspa?threadid=300428 have solution private , have talk microsoft.  can't imagine idea of having stations setup unique per station, generic accounts beyond rdsh can handle.


"those fear darkness have never seen light can do." magic: gathering

hi,

there no feature prevent active session being connected different workstation, , disconnecting current user.  allow reconnection original client setting applied citrix sessions, not rdp connections.

in general, each person expected have unique user name/password use connect.  if users share credentials, see problem describe potentially other problems security related.  know there special cases having generic accounts make sense, there are limitations , tradeoffs involved having configured way.

-tp



Windows Server  >  Remote Desktop Services (Terminal Services)



Comments

Popular posts from this blog

Motherboard replacement

Cannot create Full Text Search catalog after upgrading to V12 - Database is not fully started up or it is not in an ONLINE state

Remote Desktop App - Error 0x207 or 0x607