Security – Domain User can RDP into Domain Controller

active-directorygroup-policyremote desktopSecuritywindows-server-2008

Vanilla Windows Server 2008 x64 Standard DC (AD, DNS). I was remoting into my DC to do a bit of work and, thru force of habit, logged into the server using a regular domain account, not a domain admin. I was shocked to see that I was able to RDP into this box! Why would that be? I'm looking thru the policy and for Domain Controllers "Allow log on through Terminal Services" is "Not Defined". The user account I was using is not a member of the Domain Admins group. Is there any other policy modeling I can use to figure out why this user account was able to log into a domain controller?

Best Answer

There is a built-in group called Remote Desktop Users that can RDP into domain controllers. Check to see which accounts are in that group.

Related Topic