Bloquear sesiones de terminal server
Locking Down Windows Server 2003 Terminal Server Sessions
Microsoft Corporation
Published: July, 2003
Abstract
This article demonstrates the ability of Active Directory® to restrict Microsoft® Windows Server™ 2003 Terminal Server sessions to the functionality allowed by an administrator. Highlighting important grouppolicies, considerations are outlined for configuring user interactions with the operating system for a wide variety of deployments.
This is a preliminary document and may be changed substantially prior to final commercial release of the software described herein
The information contained in this document represents the current viewof Microsoft Corporation on the issues discussed as of the date of publication. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information presented after the date of publication.
This document is for informational purposesonly. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, AS TO THE INFORMATION IN THIS DOCUMENT.
Complying with all applicable copyright laws is the responsibility of the user. Without limiting the rights under copyright, no part of this document may be reproduced, stored in or introduced into a retrieval system, or transmitted in any form or by any means (electronic,mechanical, photocopying, recording, or otherwise), or for any purpose, without the express written permission of Microsoft Corporation.
Microsoft may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering subject matter in this document. Except as expressly provided in any written license agreement from Microsoft,the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other intellectual property.
The example companies, organizations, products, people and events depicted herein are fictitious. No association with any real company, organization, product, person or event is intended or should be inferred.© 2003 Microsoft Corporation. All rights reserved.
Microsoft, Windows, the Windows log, and Windows Server are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries.
The names of actual companies and products mentioned herein may be the trademarks of their respectiveowners.
Contents
Introduction 1
How can this be implemented? 1
Planning 2
Installing Terminal Server 3
Restrictive Computer Policies 4
Restrictive User Policies 7
Non-Policy Settings 20
Disable Internet Explorer Search Companion 20
Remove Printers and Faxes from New Start Menu 20
Disable the Full Path in Windows Explorer 21
RemoveInternet Explorer and Windows Explorer from the Quick Launch Bar 21
Disable Help 21
Network Browsing by Using the Common Open/Save File Dialog Box 21
Additional Restrictions 23
Software Restriction Policies 23
Internet Explorer in Kiosk Mode 23
Summary 24
Related Links 25
Introduction
Using Terminal Server in Windows Server 2003, you can operate 32-bitapplications, such as Microsoft Word and Microsoft Excel, anytime and anywhere. Terminal Server provides centralized application processing, management, and maintenance. With this flexibility, Terminal Server can be used in a wide variety of applications and environments.
A terminal can reside in an office, kiosk, classroom, laboratory, on a factory floor, or across the internet in another country...
Regístrate para leer el documento completo.