Domain Group Policy remote Desktop Authorization
1. Environmental introduction
Server server2012: AD01.test.cn (domain administrator: administrator)
Client win7:testpc1.test.cn (domain account: sz1)
The client testpc1 has joined the domain, and the domain account sz1 is under the OU of SZ, with the permission of Domain users.
Requirements: set group policy on the AD01 server, turn off the testpc1 client firewall and turn on the remote desktop service.
2. Steps
a. On the server, click [Service Manager]-[tools]-[Group Policy Management]
b. In Group Policy Management, expand [Forest test.cn]-- [Domain]-- [test.cn], right-click on test.cn, and select [create GPO in this domain and link here]
c. Name: Permit Remote Desktop Service-right-click and select "Edit". In the Group Policy Management Editor, select "computer configuration"-- "Policy"-- "Administrative template"-- "windows component".
d. Select "remote Desktop Services"-"remote Desktop session Host"-"Connect", double-click "allow users to connect remotely by using remote Desktop Services" on the right, and click "enable" to OK.
e. Go back to the Group Policy Management Editor, select * * computer configuration * *-- * * Policy * *-- * * Administrative template * *-- * * windows Settings * *-- * * restricted Group * *, and then right-click * * add Group * *-the member selection of this group: test\ Domain Users, which belongs to the selection of Remote Desktop Users (optional)-OK.
f. Go back to the Group Policy Management Editor, select [computer configuration]-- [Policy]-- [Administrative template]-- [Network]-- [Network connections]-- [Windows Firewall], double-click [Windows Firewall: protect all network connections] and click [disable] OK. (turn off windows Firewall)
3. Run on the server and the client: gpupdate / force
4. Client verification