- Create AD group, for example: "TS Users"
- Put the group in local "Remote Desktop Users" group on the terminal server.
- Put the terminal server in local "Terminal Server Computers" group on the "TS licensing" server to enable to read licensing information.
- Put the terminal server in separate OU and create a GPO. The GPO "Security Filtering" should include the terminal server itself and "TS Users" group. This will disable all limitation for administrators. Do not include administrators in "TS Users". Remove "All Authenticated" group from the GPO "Security Filtering"
Monday, June 29, 2009
Windows 2008 Terminal services
To configure access: