Preventing windows XP from logging into Load Balancer

With Windows XP support essentially ended earlier this year, I was wondering if there was a way to prevent a computer running XP from logging into my hosted environment via RDP (Terminal Services 2008R2) protocol. Let's say for example that someone has a
windows XP machine compromised with a key logger...I would need a way to prevent that computer from logging into my environment.
I've looked at trying to get a GPO to block RDP Client settings based on protocol however XP and Vista share the same V7 RDP protocol.
Any Suggestions?
 

Hi,
Thank you for posting in Windows Server Forum.
From your description it seems that you want to block particular windows XP computer to access the RDS Server. If this is the case, then you can do following different steps.
You can configure RD Gateway with RD CAP and RD RAP policy to control the access from computers and users and force the computer to use the RD Gateway setting.
The other one, you can filter traffic in your router or firewall to deny traffic to the terminal server from certain ports or IP addresses. (Quoted form below thread).
More information.
exclude computers from access to terminal server
http://social.technet.microsoft.com/Forums/windowsserver/en-US/09695fb9-3344-4f0a-b8c9-2c48c1704e5b/exclude-computers-from-access-to-terminal-server
Hope it helps!
Thanks.
Dharmesh Solanki

Similar Messages

  • Safari for Windows will not log into IIS sites with Windows Authentication

    Safari for Windows will not log into IIS sites with Windows Authentication enabled. The IIS log has thousands of login attempts from Safari that result in 401 errors.
    I disable Windows Authentication on IIS and it works fine. The problem with that is that my Windows clients stop working properly with seemless logins when I disable this.
    The expected behavior is that Safari will work with basic authentication when NTLM does not work. That would result in a password prompt followed by a successful login instead of Safari stopping at "Loading" while hammering the IIS logs.
    It does this on all machines that I have tried.
    Any ideas or is this a bug?

    I noticed that as well. I have to wonder if it's due to not making note of the the different end of line characters between Mac OS X and Windows in code.

  • Any way to prevent XP machines from logging onto domain?

    We've just completed upgrading our hundreds of XP workstations however, I am concerned that there could still be a laptop or two sitting in someones car that will eventually make it's way back in. Is the any way I can prevent XP machines from logging onto
    the network/domain?

    Hi,
    Checkout the below thread on similar discussion and steps to solve your requirement,
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/986bc78e-0ade-47a1-9e14-fc46f4cad24d/group-policy-restrict-all-xp-computer-to-log-into-domain?forum=winserverGP
    Hope this information will be helpful to you.
    Recommended: You can test this scenario in a test environment before moving ahead to production.
    Regards,
    Gopi
    www.jijitechnologies.com

  • Firefox 4 is preventing windows 7 from shutting down

    When I am shutting my pc off and firefox 4 is running I get this"firefox 4 is preventing windows 7 from shutting down "

    https://support.mozilla.com/en-US/kb/Firefox%20hangs <br />See '''hang-at-exit'''

  • Having problem with svchost.exe/ntdll.dll errors causing GPSVC (Group Policy Client) to crash preventing users from logging into the server.

    Recently (within the past 2 weeks) I have noticed a few of our servers will have problems with the svchost.exe application causing the GPSVC (Group Policy Client) to crash. The only fix at that point is to reboot the server since the GPSVC service is tied
    to svchost.exe and therefore is protected from being manually restarted.
    I noticed the following errors when this occurs:
    Log Name:      Application
    Source:        Application Error
    Date:          7/23/2013 4:35:26 AM
    Event ID:      1000
    Task Category: (100)
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      Server1.xxx.xxx.net
    Description:
    Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
    Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e
    Exception code: 0xc0000024
    Fault offset: 0x00000000000cd7d8
    Faulting process id: 0x46c
    Faulting application start time: 0x01ce877f9476ac07
    Faulting application path: C:\Windows\system32\svchost.exe
    Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
    Report Id: d252d26d-f372-11e2-8ad4-005056ac00e8
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Application Error" />
        <EventID Qualifiers="0">1000</EventID>
        <Level>2</Level>
        <Task>100</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2013-07-23T08:35:26.000000000Z" />
        <EventRecordID>158950</EventRecordID>
        <Channel>Application</Channel>
        <Computer>AAW19XM2.agency.nwie.net</Computer>
        <Security />
      </System>
      <EventData>
        <Data>svchost.exe</Data>
        <Data>6.1.7600.16385</Data>
        <Data>4a5bc3c1</Data>
        <Data>ntdll.dll</Data>
        <Data>6.1.7601.17725</Data>
        <Data>4ec4aa8e</Data>
        <Data>c0000024</Data>
        <Data>00000000000cd7d8</Data>
        <Data>46c</Data>
        <Data>01ce877f9476ac07</Data>
        <Data>C:\Windows\system32\svchost.exe</Data>
        <Data>C:\Windows\SYSTEM32\ntdll.dll</Data>
        <Data>d252d26d-f372-11e2-8ad4-005056ac00e8</Data>
      </EventData>
    </Event>
    All of our servers are running Server 2008 R2 Enterprise where we use Citrix to deliver desktop sessions to our users, but some are virtual and some are physical. This seemingly impacts our virtual machines more, and our VMs are hosted through VMWare, however,
    about 5 months ago a similar error fired on a non-virtual machine:
    Log Name:      Application
    Source:        Application Error
    Date:          2/27/2013 6:57:58 AM
    Event ID:      1000
    Task Category: (100)
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      AAW29033
    Description:
    Faulting application name: svchost.exe_gpsvc, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
    Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e
    Exception code: 0xc0000024
    Fault offset: 0x00000000000cd7d8
    Faulting process id: 0x6c0
    Faulting application start time: 0x01ce14e1af313fd9
    Faulting application path: C:\Windows\system32\svchost.exe
    Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
    Report Id: ed3d01c4-80d4-11e2-9128-b499baa9e5e8
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Application Error" />
        <EventID Qualifiers="0">1000</EventID>
        <Level>2</Level>
        <Task>100</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2013-02-27T11:57:58.000000000Z" />
        <EventRecordID>286291</EventRecordID>
        <Channel>Application</Channel>
        <Computer>AAW29033</Computer>
        <Security />
      </System>
      <EventData>
        <Data>svchost.exe_gpsvc</Data>
        <Data>6.1.7600.16385</Data>
        <Data>4a5bc3c1</Data>
        <Data>ntdll.dll</Data>
        <Data>6.1.7601.17725</Data>
        <Data>4ec4aa8e</Data>
        <Data>c0000024</Data>
        <Data>00000000000cd7d8</Data>
        <Data>6c0</Data>
        <Data>01ce14e1af313fd9</Data>
        <Data>C:\Windows\system32\svchost.exe</Data>
        <Data>C:\Windows\SYSTEM32\ntdll.dll</Data>
        <Data>ed3d01c4-80d4-11e2-9128-b499baa9e5e8</Data>
      </EventData>
    </Event>
    I've searched and cannot seem to find any information as to what may be causing this, or even really where to start. Would someone be able to help me identify what might be causing this event, specific with the Exception code: 0xc0000024, which causes
    the Group Policy Client service to stop?

    You still out there looking at things? If so I have an update. The issue hasn't stopped, even though it did seemingly die down for awhile, however, it is now back with a vengeance.
    I am able to force it to happen by killing the svchost process that is hosting GPSVC. If I run gpupdate /force, then logout/login it does get GPSVC running again. Furthermore, if I simply start svchost again via the Task Manager GPSVC starts running again.
    When I access the server remotely with KVM it acts just like it does as if I'm logging into it via Citrix/RDP which for Admin IDs gives an error saying "Failed to connect to a windows service. Windows could not connect to the Group Policy Client service...",
    however, normal user accounts just get a message when logging into the server "The Group Policy Client Service Failed the Logon. Access is denied."
    I haven't opened a case with Microsoft yet, but we about ready to because of the increase in these errors.
    If you have any further suggestions that would be great, otherwise I'll provide an update once I get word back from Microsoft.
    **EDIT -- apparently I mistook the the server's SCM's actions as my own. I was able to successfully crash the GPSVC service by killing the hosting svchost process, however, after I crashed it and let it sit crashed for awhile when I attempted
    to restart either by starting a svchost task, or running gpupdate /force it failed. Either that, or there is a timing issue where if we don't restart the svchost process, or run gpupdate /force quickly enough it won't be able to recover without a reboot.

  • How do I prevent users from logging into my machine in single user mode?

    I established an standard accounts for my family.  My son figured out that if he logs into the machine in Single User mode that he logs in as the root user.  He then proceeded to create another user with administrative privileges and change his account to administrator then delete the other account.  Funny thing about this is that as much as OS X is secure from outside threats a simple command-s gets you right into the very heart of the machine......

    You can set a firmware password. The firmware password only allows you to start up in normal mode, so if you try to start in single-mode user or safe mode, your Mac will ask you for a password.
    The process to turn it on depends on the OS X version you have. Open  > About this Mac, check the Mac OS X version and follow the steps depending on your OS X version.
    If you have 10.7 or 10.8:
    1. Hold Command and R keys while your Mac is starting up.
    2. After starting up into OS X Utilities, go to Utilities menu (on the menu bar) > Firmware Password Utility, and enable the firmware password.
    3. Restart the Mac.
    If you have 10.6 or older:
    1. Insert the Mac OS X disc and hold the C key while your Mac is starting up.
    2. Choose your language, go to Utilities menu (on the menu bar) > Firmware Password Utility, and enable the firmware password.
    3. Restart the Mac.
    Also, this will protect your Mac against thieves because they won't be able to erase the hard drive without knowing the firmware password. Don't forget the password, because only Apple can reset it if you don't know this password

  • Way to prevent certain OD users from logging into certain computers?

    Hi, I have a machine group of computers I don't want some network users logging into.  Can I do this somehow? 

    Hi
    Yes.
    Select the desired Computer Group. Click on the Preferences Icon. Click on the Login Icon. Click the Access Tab. The rest should be fairly obvious.
    HTH?
    Tony

  • How do I keep my Airport Extreme from logging into other networks?

    How can I tell my network to always log into our network and ignore the other signals it finds?
    In older MacOS's you could tell WiFi to only use trusted networks. My problem is that in my neighborhood there are lots of WiFi users and my airport network is always trying to use one of them (even though the signal strength is the same). The most annoying is Comcast, which seems to show up the most. I have Comcast for TV etc., but have the WiFi feature disabled on the modem. I want more control. Yesterday it got on one of my neighbors that isn't even secure?

    1. Have you ticked to "Ask to join new networks" ??
    2. Have you deleted all the other possible wireless networks from your listing.
    The network which should be the first in the list will be the one that is connected first. But we find it is best to empty the list.
    Maybe also check to require admin authorisation to change networks.
    Other than those things nothing else is offered..
    I have many wireless networks here and I have not seen the issue even on Mavericks.. but if any OS is going to give you grief Mavericks is the one.

  • Flex preventing ColdFusion server from logging exceptions!

    Hello all,
    Whenever I invoke a CFC from Flex, if the CFC throws an
    exception, that exception is not logged in the ColdFusion server
    logs. I built an html page that invokes the same page, and when the
    exception is thrown it is indeed logged on the server.
    Why is Flex preventing ColdFusion from logging the
    exceptions!?

    I've never realized that but you can add a cflog tag to your
    CFC or debug the error taking a look at the stacktrace withing FB
    debugger.

  • How can I prevent a tab from chaning into a new window by itself

    When I play a video, and open another tab, the tab with the video will sometimes change into a whole new window. I don't click anything specific to make the tab change into a window, it will just do it a few minutes after I open the new tab. Does anyone have a clue on how to prevent this. Thank you!

    Make sure that you do not drag a tab in the browser window.<br />
    Current Firefox versions have a feature called tear-off tabs.<br />
    You can detach a tab from the current window and open it in a new window by dragging a tab in the browser window.<br />
    You can drag that tab back to the tab bar in the original window to undo that detaching.
    bug489729 (Disable detach and tear off tab):
    * https://addons.mozilla.org/firefox/addon/bug489729-disable-detach-and-t

  • Preventing an application from logging to Console

    Hi,
    I play Urban Terror to unwind, and recently I discovered that it sends every on-screen message (such as, X was Hit in the Kevlar for 29% damage) to the Console. This is ridiculous and accounts for several thousand entries in a 30-min session. I have asked for advice on the UrT forums, but the only response I got was wholly disrespectful and just told me to deal with it.
    So, does anyone know how I can intercept all log messages from Urban Terror and prevent them from being added to the Console?
    Thanks.

    Hi,
    Those who need to know how to implement this can find the result here.
    S.

  • Preventing Windows 7 From Automatically Shutting Down

    Hi there,
    I am transferring a large amount of data and need to leave the PC on overnight. I believe I have configured Windows so that automatic restarts for updates are disabled, yet the PC still sometimes shuts down when left on for long periods.
    Any advice on how to prevent automatic shutdowns is hugely appreciated.
    Many thanks...

    If your computer is actually shutting down and not going into sleep mode then you probably need to look in task scheduler and see if there is a task that launches "C:\Windows\System32\shutdown.exe" at some scheduled time.
    If the PC is actually just going into sleep mode then use Control Panel to alter your power plan in System and Security, power options.
    It may even be possible that the BIOS has a setting for your PC to turn off at some point. Although I doubt that but would check the BIOS settings.
    La vida loca

  • How to Prevent Windows 10 from Spying Full Guide

    Easily make Windows 10 stop spying on you.
    Easy to follow step by steps to secure your Windows 10 and prevent sensitive information leaking....
    Read More
    This topic first appeared in the Spiceworks Community

    Team Folder in the past was managed by administrators. Administrator can create, edit, delete team folders. The team folder can be published to a group of users, including Active Directory group. It is very convenient to share files and folders with a group of users in the same team. As team groups bigger, it may not be convenient for administrator to manage all the team folders. So it makes sense for administrator to assign some users to be able to manage team folder that they own themselves. Role Manager It usually starts with the role manager by creating a role with Add/Edit/Delete permissions and assign it to users or Active Directory groups. Manage Team Folder The user who are in the private team folder role will be able to manage team folders without seeing all the team folders from everyone. Here is a YouTube Video about...

  • Prevent Windows Search from indexing PST contents in Outlook

    Running Windows 8.1 with Windows Search, and Office 2013 with more that 20GB in more than 10 PSTs and OSTs, searching becomes very slow after indexing everything. Reindexing has no change. If I exclude Outlook it's very fast.
    There is an option in Outlook search ribbon -> Search Tools -> Locations to search. I removed most of the PSTs (accounting for 75% of the contents), but still ALL PSTs and OSTs get indexed (although they won't be searched).
    This makes using Windows Search nearly impossible (e.g. searching using the charm thing takes 30 seconds).
    How can I have Windows Search index ONLY the PSTs and OSTs that I specifically want?
    Is there any configuration, registry stuff or programatic workaround to exclude from indexing (not searching)?
    Thank you.
    Andy.PT

    Hi,
    Still, as mentioned above, I don't have such a method to choose which to be included in Indexing and which to be excluded.
    The only thing that I find which is close to your request is this:
    If the method above isn't helpful in your scenario(as you mentioned), you can try some 3rd-party tools/add-ins to realize a new search function which may meet your request.
    Regards,
    Melon Chen
    Forum Support
    Come back and mark the replies as answers if they help and unmark them if they provide no help.
    If you have any feedback on our support, please click
    here.

  • SG 300 seems to be preventing Windows systems from get an IP via Windows server DHCP

    All the basics from the server are working and have been for years. I would appreciate not being asked to check the basics as "is the DHCP server registered".
    There seems to be an issue where the VLAN is preventing DHCP from working. I have also read that MAC addresses don't get registered until there is a write. The issue also seems to roam. It affects different PC's at different times. I had this issue with this switch approximately a year ago.
    Can I at least get some direction until I can post the firmware version and config. Its a busy small business and this issue is extremely unpredictable.
    Thank you

    Hi
    check if you have DHCP snooping disabled (at least try to turn it off and see if it helps)
    check if you are running Rapid version of STP protocol
    check if all ports toward end-user devices are configured as spanning-tree portfast ports. if you are not use portfast, your port transition to forwarding state could takes longer time resulted that all DHCP discover packets from client will be just dropped on switchport site until port transits to forwarding state.

Maybe you are looking for

  • How do you add play list from itunes to ipod on windows 8.1

    I would like to create a new play list on my I pod nano Generation 4. I have the the music in my I TUNES library as files and as a playlist . How do I get this to my I pod. Thanks for any help FCiurczak

  • ESS Leave Request Edit

    Hi All, We are working on ECC 5.0 and ENT portal 6.0 User has applied the leave in ESS, which is yet not approved. Business want this leave request to be editable before it gets approved. Please guide me on this, how this can be done??? Regards, Aman

  • Selective deletion of data from ODS

    Hai,          I need to delete selectively data from an ODS. I know that I have the option of selective deltionin cube. But how can I delete them in ODS? Thank you.

  • Idvd project with video and slideshow for dvd-rom file access

    working on an idvd project with both a video section and photos in a few photo galleries. its' a slightly more complex project, but still only 2gb on a 4gb disc. After we burn (with all dvd-rom contents checked, and advance>edit dvd-rom contents show

  • Finder is unusable

    I recently upgraded to Mavericks and all was going well untill I restarted and went into Bootcamp for about five mins when I restarted into the mac side of things all **** broke loose. My finder windows have disappeared. I can see that they are open