Administrative shares on RDS server?


hi,

can explain why domain users can access administrative on rds server when logged in on server?

they can access them when logged in on rds. when try access them local computers can't access them.

i don't want users able browse administrative shares when logged in on terminal. goes beyond purpose of hiding , denying drive access while still can use administrative share.

regards,


hi,

administrative shares hidden network shares created windows nt family of operating systems allow system administrators have remote access every disk volume on network-connected system.

when users remotely log rds server, have user sessions locally on rds server, therefore, can access administrative shares locally. avoid this, can modify ntfs permissions (under security tab) on corresponding files. once deny ntfs permissions assigned, remote desktop users can access files neither locally nor remotely.

more information you:

administrative share

http://en.wikipedia.org/wiki/administrative_share

best regards,

amy


please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Security



Comments

Popular posts from this blog

Motherboard replacement

Cannot create Full Text Search catalog after upgrading to V12 - Database is not fully started up or it is not in an ONLINE state

Remote Desktop App - Error 0x207 or 0x607