configmgr remote tools group
Hi AllI'm trying to find out if there is a way to exclude servers from having this group on them. We have some very critical server that should not have this user group there because the group that is added to permitted viewers should not be able to access these server. How do i exclude servers from this group.You guys help will really be appreciated.Thanks in Advance
January 29th, 2010 12:05pm
You can't restrict access to a specific group of servers like this. The only workaround I know of would be to deploy a separate SCCM Site and point the servers to the second site, locking down the access on that site.Scott Gill
SCCM Consultant
Free Windows Admin Tool Kit Click here and download it now
January 29th, 2010 7:35pm
Why not just use the setting that requires the end user to give permission to let people do remote tools sessions? That would effectively prevent anyone from using remote tools to login to the servers. Also if nobody is logged into the server I don't think remote tools will connect. I don't use remote tools in sccm but I do know that a huge compaint about it is the inabilty to remote into a comptuer that has not logged in user.Also I thnk you can remove the "use remote tools" right for a specific collection. According to the docs that's not fool proof but someone would have to want in bad enough to seup a rogue sccm server. http://technet.microsoft.com/en-us/library/bb694296.aspxAnother option, this is just me thinking out loud and may not work, would be to use a machine startup script to remove the group from the servers. That would need to be throughly tested in a lab and like I said may not work.
John Marcum | http://www.TrueSec.com/en/Training.htm | http://myitforum.com/cs2/blogs/jmarcum
January 29th, 2010 8:15pm
Also thinking out loud, maybe it's an idea to use a Ristricted Groups GPO on those servers that empties the group again.My Blog: http://www.petervanderwoude.nl/
Free Windows Admin Tool Kit Click here and download it now
January 29th, 2010 10:10pm
Hi GuysThanks alot for all the info, will try them and let you know.Thanks Again
February 3rd, 2010 10:33am