Allow security group to rdp to certain computer OU only












0















Basically I am trying to replicate my work Active Directory at home for educational purposes.



At work we have computers and laptops from different sites grouped into different OU e.g Laptop1 and Computer1 would be in BRISTOL OU, and Laptop2 and Computer2 would be in BIRMINGHAM OU,



My manager can RDP to any site because of his permissions (which I totally agree with) and I can only RDP to the computers of site BRISTOL, now I know that it will be to do with a security group and group policies.



I just want to know what group policy settings will allow you assign Remote Access to different OU in group policy.



Thanks.










share|improve this question























  • Do you have the necessary permissions on the domain to even make these changes?

    – Ramhound
    Jan 26 at 20:10











  • It's on a home lab that I've setup just to replicate my work organisation.

    – jimbob
    Jan 26 at 21:40











  • I assume your trying to determine what changes must be done to modify the work organization by having the home lab or are you trying to simply configure the home lab similar to the work organization?

    – Ramhound
    Jan 26 at 21:57











  • Just trying to make the home lab similar to the work environment, to get a better understanding without messing up anything in the work environment.

    – jimbob
    Jan 26 at 22:15
















0















Basically I am trying to replicate my work Active Directory at home for educational purposes.



At work we have computers and laptops from different sites grouped into different OU e.g Laptop1 and Computer1 would be in BRISTOL OU, and Laptop2 and Computer2 would be in BIRMINGHAM OU,



My manager can RDP to any site because of his permissions (which I totally agree with) and I can only RDP to the computers of site BRISTOL, now I know that it will be to do with a security group and group policies.



I just want to know what group policy settings will allow you assign Remote Access to different OU in group policy.



Thanks.










share|improve this question























  • Do you have the necessary permissions on the domain to even make these changes?

    – Ramhound
    Jan 26 at 20:10











  • It's on a home lab that I've setup just to replicate my work organisation.

    – jimbob
    Jan 26 at 21:40











  • I assume your trying to determine what changes must be done to modify the work organization by having the home lab or are you trying to simply configure the home lab similar to the work organization?

    – Ramhound
    Jan 26 at 21:57











  • Just trying to make the home lab similar to the work environment, to get a better understanding without messing up anything in the work environment.

    – jimbob
    Jan 26 at 22:15














0












0








0


0






Basically I am trying to replicate my work Active Directory at home for educational purposes.



At work we have computers and laptops from different sites grouped into different OU e.g Laptop1 and Computer1 would be in BRISTOL OU, and Laptop2 and Computer2 would be in BIRMINGHAM OU,



My manager can RDP to any site because of his permissions (which I totally agree with) and I can only RDP to the computers of site BRISTOL, now I know that it will be to do with a security group and group policies.



I just want to know what group policy settings will allow you assign Remote Access to different OU in group policy.



Thanks.










share|improve this question














Basically I am trying to replicate my work Active Directory at home for educational purposes.



At work we have computers and laptops from different sites grouped into different OU e.g Laptop1 and Computer1 would be in BRISTOL OU, and Laptop2 and Computer2 would be in BIRMINGHAM OU,



My manager can RDP to any site because of his permissions (which I totally agree with) and I can only RDP to the computers of site BRISTOL, now I know that it will be to do with a security group and group policies.



I just want to know what group policy settings will allow you assign Remote Access to different OU in group policy.



Thanks.







windows remote-desktop active-directory group-policy windows-server






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Jan 26 at 20:06









jimbobjimbob

228




228













  • Do you have the necessary permissions on the domain to even make these changes?

    – Ramhound
    Jan 26 at 20:10











  • It's on a home lab that I've setup just to replicate my work organisation.

    – jimbob
    Jan 26 at 21:40











  • I assume your trying to determine what changes must be done to modify the work organization by having the home lab or are you trying to simply configure the home lab similar to the work organization?

    – Ramhound
    Jan 26 at 21:57











  • Just trying to make the home lab similar to the work environment, to get a better understanding without messing up anything in the work environment.

    – jimbob
    Jan 26 at 22:15



















  • Do you have the necessary permissions on the domain to even make these changes?

    – Ramhound
    Jan 26 at 20:10











  • It's on a home lab that I've setup just to replicate my work organisation.

    – jimbob
    Jan 26 at 21:40











  • I assume your trying to determine what changes must be done to modify the work organization by having the home lab or are you trying to simply configure the home lab similar to the work organization?

    – Ramhound
    Jan 26 at 21:57











  • Just trying to make the home lab similar to the work environment, to get a better understanding without messing up anything in the work environment.

    – jimbob
    Jan 26 at 22:15

















Do you have the necessary permissions on the domain to even make these changes?

– Ramhound
Jan 26 at 20:10





Do you have the necessary permissions on the domain to even make these changes?

– Ramhound
Jan 26 at 20:10













It's on a home lab that I've setup just to replicate my work organisation.

– jimbob
Jan 26 at 21:40





It's on a home lab that I've setup just to replicate my work organisation.

– jimbob
Jan 26 at 21:40













I assume your trying to determine what changes must be done to modify the work organization by having the home lab or are you trying to simply configure the home lab similar to the work organization?

– Ramhound
Jan 26 at 21:57





I assume your trying to determine what changes must be done to modify the work organization by having the home lab or are you trying to simply configure the home lab similar to the work organization?

– Ramhound
Jan 26 at 21:57













Just trying to make the home lab similar to the work environment, to get a better understanding without messing up anything in the work environment.

– jimbob
Jan 26 at 22:15





Just trying to make the home lab similar to the work environment, to get a better understanding without messing up anything in the work environment.

– jimbob
Jan 26 at 22:15










1 Answer
1






active

oldest

votes


















1














RDP control to a given computer is based on the user account attempting the RDC being in, or in a group within the local computer's Remote Desktop User's group.



The normal way to place AD user objects or security groups within that local group is using a Group Policy.



Group Policies can be applied to specific objects or groups of objects based on a very wide array of criteria, ranging from the Organization Unit (OU) they exist within to really any criteria that can be queried by Windows Management Instrumentation (WMI).



The easiest way to assign individual security groups to the Remote Desktop User local group of the computers within a specific OU is to Link and Activate a group policy on that specific OU that assigns the AD users/groups to the local group. You'll find this policy under Computer Configuration Preferences Control Panel Settings Local Users and Groups.






share|improve this answer
























  • That's perfect, exactly what I am looking for. Thank you.

    – jimbob
    Jan 29 at 8:59











Your Answer








StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "3"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1398797%2fallow-security-group-to-rdp-to-certain-computer-ou-only%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























1 Answer
1






active

oldest

votes








1 Answer
1






active

oldest

votes









active

oldest

votes






active

oldest

votes









1














RDP control to a given computer is based on the user account attempting the RDC being in, or in a group within the local computer's Remote Desktop User's group.



The normal way to place AD user objects or security groups within that local group is using a Group Policy.



Group Policies can be applied to specific objects or groups of objects based on a very wide array of criteria, ranging from the Organization Unit (OU) they exist within to really any criteria that can be queried by Windows Management Instrumentation (WMI).



The easiest way to assign individual security groups to the Remote Desktop User local group of the computers within a specific OU is to Link and Activate a group policy on that specific OU that assigns the AD users/groups to the local group. You'll find this policy under Computer Configuration Preferences Control Panel Settings Local Users and Groups.






share|improve this answer
























  • That's perfect, exactly what I am looking for. Thank you.

    – jimbob
    Jan 29 at 8:59
















1














RDP control to a given computer is based on the user account attempting the RDC being in, or in a group within the local computer's Remote Desktop User's group.



The normal way to place AD user objects or security groups within that local group is using a Group Policy.



Group Policies can be applied to specific objects or groups of objects based on a very wide array of criteria, ranging from the Organization Unit (OU) they exist within to really any criteria that can be queried by Windows Management Instrumentation (WMI).



The easiest way to assign individual security groups to the Remote Desktop User local group of the computers within a specific OU is to Link and Activate a group policy on that specific OU that assigns the AD users/groups to the local group. You'll find this policy under Computer Configuration Preferences Control Panel Settings Local Users and Groups.






share|improve this answer
























  • That's perfect, exactly what I am looking for. Thank you.

    – jimbob
    Jan 29 at 8:59














1












1








1







RDP control to a given computer is based on the user account attempting the RDC being in, or in a group within the local computer's Remote Desktop User's group.



The normal way to place AD user objects or security groups within that local group is using a Group Policy.



Group Policies can be applied to specific objects or groups of objects based on a very wide array of criteria, ranging from the Organization Unit (OU) they exist within to really any criteria that can be queried by Windows Management Instrumentation (WMI).



The easiest way to assign individual security groups to the Remote Desktop User local group of the computers within a specific OU is to Link and Activate a group policy on that specific OU that assigns the AD users/groups to the local group. You'll find this policy under Computer Configuration Preferences Control Panel Settings Local Users and Groups.






share|improve this answer













RDP control to a given computer is based on the user account attempting the RDC being in, or in a group within the local computer's Remote Desktop User's group.



The normal way to place AD user objects or security groups within that local group is using a Group Policy.



Group Policies can be applied to specific objects or groups of objects based on a very wide array of criteria, ranging from the Organization Unit (OU) they exist within to really any criteria that can be queried by Windows Management Instrumentation (WMI).



The easiest way to assign individual security groups to the Remote Desktop User local group of the computers within a specific OU is to Link and Activate a group policy on that specific OU that assigns the AD users/groups to the local group. You'll find this policy under Computer Configuration Preferences Control Panel Settings Local Users and Groups.







share|improve this answer












share|improve this answer



share|improve this answer










answered Jan 28 at 17:02









music2myearmusic2myear

31.7k858101




31.7k858101













  • That's perfect, exactly what I am looking for. Thank you.

    – jimbob
    Jan 29 at 8:59



















  • That's perfect, exactly what I am looking for. Thank you.

    – jimbob
    Jan 29 at 8:59

















That's perfect, exactly what I am looking for. Thank you.

– jimbob
Jan 29 at 8:59





That's perfect, exactly what I am looking for. Thank you.

– jimbob
Jan 29 at 8:59


















draft saved

draft discarded




















































Thanks for contributing an answer to Super User!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1398797%2fallow-security-group-to-rdp-to-certain-computer-ou-only%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Plaza Victoria

Puebla de Zaragoza

Musa