Forum Discussion
HungryMoo
Aug 14, 2023Copper Contributor
How to enable Remote Desktop on to Domain Controllers for non admins
Hello, Our cyber team needs remote desktop access to our domain controllers for read purposes. They're part of the built-in "remote desktop users" group, but that doesn't give them RDP access. I th...
MathieuVandenHautte
Aug 15, 2023Iron Contributor
Hi HungryMoo,
I advice:
- only allowing domain administrators logging in to domain controllers
- prevent using Remote Desktop to interactively manage domain controllers
- never using the Remote Desktop Users group (in general: never use built-in groups)
- implementing a secure administrative "jump server" architecture
- HungryMooAug 15, 2023Copper ContributorThanks Mathieu,
"never using the Remote Desktop Users group (in general: never use built-in groups)" - the group is empty by default. The obvious question being, if they're never intended for use, why have them in the first place?