B
Bob
Hi,
I'm just getting started with R2 and reading through the documentation I'm
trying to learn if the following is possible.
I have three groups:
fullremotedesktop - members of this group can use remote desktop in the
traditional way to get complete access to the server using mstsc, just like
if I used remote desktop do access an XP computer
fullwebapps - members of this group can only run programs through the webapp
interface. The can't remote into the server in the old, traditional way.
The webapps get full access to local resources, like printer, clipboard,
drives, etc.
restrictedwebapps - members of this group can only run webapps and the only
local resource they can have access to is the local printer or printers
installed on the remote desktop services server.
The reason for this division is that only admins should be able to get into
the server, permanent staff get the web apps and local resources, temporary
staff get webapps, but can't store a file locally or copy to the clipboard.
Is this possible? If not, can I at least have two groups: full
remotedesktop users and webapp only users? If I use the log on locally
permission, will that stop people from using webapps as well since
techincally they are logging on locally? I'd test it, but if I lock myself
out I don't want to have to drive back into work on a Saturday.
Thanks!
I'm just getting started with R2 and reading through the documentation I'm
trying to learn if the following is possible.
I have three groups:
fullremotedesktop - members of this group can use remote desktop in the
traditional way to get complete access to the server using mstsc, just like
if I used remote desktop do access an XP computer
fullwebapps - members of this group can only run programs through the webapp
interface. The can't remote into the server in the old, traditional way.
The webapps get full access to local resources, like printer, clipboard,
drives, etc.
restrictedwebapps - members of this group can only run webapps and the only
local resource they can have access to is the local printer or printers
installed on the remote desktop services server.
The reason for this division is that only admins should be able to get into
the server, permanent staff get the web apps and local resources, temporary
staff get webapps, but can't store a file locally or copy to the clipboard.
Is this possible? If not, can I at least have two groups: full
remotedesktop users and webapp only users? If I use the log on locally
permission, will that stop people from using webapps as well since
techincally they are logging on locally? I'd test it, but if I lock myself
out I don't want to have to drive back into work on a Saturday.
Thanks!