Screen Sharing Disabled Per User?

Hi, this is a repost from OSX usability forums...hopefully someone can help here:
I caught a kid cheating this morning by utilizing Screen Sharing to see what his neighbor was answering on a test. I would like to disable Screen Sharing as it pertains to the user, but I still need to run Remote Desktop and see all machines at the admin level. Each kid has an OpenDirectory account, so would it be possible to block at that level?

Block the Screen Sharing application. If the accounts are OD accounts, just add this to the MCX set and start enforcing an explicit deny on the Screen Sharing app. That should resolve it. The other option, assuming all systems have a unified admin account that the kids don't know, go into System Preferences > Sharing > Remote Management and choose "only these users" and add the local admin account only. That should set up a SACL for the ARD/Screen Sharing process to only allow access for the one user, not for all potential users of the machine.
Hope this helps

Similar Messages

  • Screen sharing and multiple users

    I have an iMac at home that is used by multiple family members. I have multiple logins enable so it is common to have 2-3 accounts logged in at once. I would like to use screen sharing to connect to my account even when one of the kids is logged into their account.
    I started by looking at the vnc processes. There is one process that run as root:
    root 21792 0.0 0.0 2437128 1736 ?? Ss 12:25PM 0:00.02 /System/Library/CoreServices/RemoteManagement/AppleVNCServer.bundle/Contents/Su pport/RFBRegisterMDNS
    Then there is another process for each person logged in:
    username 22006 0.0 0.3 2734876 13964 ?? S 12:33PM 0:00.29 /System/Library/CoreServices/RemoteManagement/AppleVNCServer.bundle/Contents/Ma cOS/AppleVNCServer
    So I have two questions. One is how can there be three processes running that listen on the same 5900 port at the same time and how does it decide which one to connect a vnc client to? My second question is how can I prevent the AppleVNCServer process from starting for each user. I've tried killing those processes but they respawn immediately.

    Hi
    Thank you for your answer. Sorry to have been unclear - I'll give it another go :o)
    Here is what I am trying to do:
    I have 2 users (Plex and Ursus) that I want to have logged on at the same time. Plex will be "in the front" i.e. that is the screen that is seen if you are at the mini. Ursus is a user that is logged on but you cannot currently see (i.e. in the back as it where). I would like to work using the user Ursus (to, for example, rip a movie from a DVD (that I own of course :o).
    Using file sharing would mean that I have 2 machines running and that I need to copy all the files from the one machine to the other, not exactly what I want but manageable.
    I have managed to get this "partly" working - I am using Vine Server for Mac (http://www.testplant.com/products/vineserver/OSX) which allows me to start a VNC server on e.g. port 5901 and then screen share to that session. If I setup the second user (Ursus in this case) to use this server then I can connect to the "back" user. The only problem being that Vine Server seems to crash with Plex - as soon as I start it Plex just hangs and randomly crashes!
    Was that clearer?
    Thanks again
    Ursus

  • Automatically accept screen sharing from specific user ???

    My mother is a newbie mac user. To be honest, she's a newbie computer user - full stop. She did inherit my PC laptop when I switched, but within a week she had crashed it. The mac she has is still running. (And guess who got it for her. I'm a good daughter.)
    Anyway - her G4 Powermac is running Leopard like a dream. In fact it is much faster now than before. Still, she has a few issues. Like the other day, she couldn't get music through her speakers and I'm abroad at the time.
    I asked her to accept a screen share, she did. I fixed the speaker issue and closed the screen share. She is happy as larry. But that got me thinking. Is it possible to automatically accept screen share from certain users? That would be a great help if that would be possible.
    Thanks in advance.

    Musicsites, here is your answer. Just follow the instructions completely and it will work quite well. I have it running and it allows my iMac to automatically answer incoming Screen Sharing requests ONLY from my MacBook.
    <http://www.getstonered.com/2007/11/applescript-automatically-accept-ichat.html>
    Mike

  • IChat Screen Sharing Disabled

    I have a MacBook 2GHz Intel Core Duo running Leopard and I've been having some problems with the screen sharing. I know people have asked this question before but I can't seem to get a straight answer. I've tried to share screens with another computer running Leopard but I can't even get to the option. The Share Screens with .... and Ask To Share Screens with .... are grayed out and I've gone into the system preferences and added the computer to my shared screens list. It's all on too.
    I can share screens through the screen sharing app but no luck on the iChat. If someone could help that would help out a lot. Thanks in advance.
    Autumnmycat

    Hi and welcome to discussions,
    Do you, your computer and your internet access meet all these requirements please?
    http://docs.info.apple.com/article.html?artnum=306687
    Actually.... you personally don't have to!
    Regards
    Ian

  • Is Screen Sharing with multiple users possible?

    I am trying to discuss some documents with multiple users. It works very well with just two users sharing the screen of one of them, so I was wondering if there was a way to have a third user participating. If iChat does not allow this, does anyone know a different software solution?
    Thanks
    Christian

    Hi,
    No. (Not in iChat)
    And I have not heard of anything either.
    10:39 PM Friday; October 22, 2010
    Please, if posting Logs, do not post any Log info after the line "Binary Images for iChat"

  • Do not allow clipboard redirection - enable/disable per user

    I have a requirement to for all users, by default, to enable the following GPO on a Windows 2008 R2 RDS server:
    "Do not allow clipboard redirection" 
    This policy is configurable in both the computer and user policies.
    When I enable the policy for the computer only it disables the use of clipboard redirection for all users.
    When I enable the policy for the user only (enabling loopback processing on the computer policy as the user is in a different OU to the server) it does not disable the use of clipboard redirection, the setting is grayed out in the RDP settings but it remains
    enabled (un-checked).
    So it would appear that the setting is only configurable (or will only work) as a computer policy. Can anyone confirm if this is an expected behavior as I have tested in both a lab and live environment with the same result?
    Cheers,
    Phil

    Hi Phil,
    Thank you for post in Windows Server Forum.
    If you disable redirection of the Clipboard, for example, users connecting remotely to the RD Session Host server on this connection will not be able to redirect their Clipboard in their remote session, even if they select the Clipboard check box on the Local
    Resources tab under Options in Remote Desktop Connection. 
    If you enable redirection of a local device or resource on the RD Session Host server, users will still have to specify that they want to redirect that type of local device or resource by making the appropriate selection on the Local Resources tab under Options
    in Remote Desktop Connection.
    Note: These Group Policy settings will take precedence over the settings configured in Remote Desktop Session Host Configuration and over the settings specified by the user in Remote Desktop Connection. If both the Computer Configuration and the User Configuration
    policy settings are configured, the Computer Configuration policy settings take precedence.
    More information:
    Make Local Devices and Resources Available in a Remote Session
    http://technet.microsoft.com/en-us/library/cc770631.aspx
    Hope it helps!
    Thanks,
    Dharmesh

  • Screen Language per User

    Hi, is there a way that I can switch the screen language from DE to EN for some users when they login?
    We use screen sharing with different users to perform some remote tasks.

    Ich glaube nicht dass arbeiten soll.
    The language is set at login, and not with the screen sharing mechanisms.
    Failing that, it's probably easiest to enable both German and English via the International Menu and let the users select. (That does effect only new windows, however.)

  • Screen sharing and login

    I've got a mini running Leopard and a MBP running Snow Leopard. I'm trying to use screen sharing in finder to connect to the mini from the MBP. There seems to be something preventing screen sharing whenever a user is logged in to the mini, even if the login occurs in screen sharing.
    Here are some examples of the behavior:
    If I'm logged in as "macuser1" on the mini, I can connect to the mini as "macuser1" or "macuser2" and see folders, etc in Finder, but, when I click the share screen button, I get a connection failed message.
    If I go to the mini and logout, then go to the MBP and connect to the mini as "macuser1" I can see folders just fine. When I click share screen it connects just fine and I see the login screen on the mini. If I enter a username and password it logs in just fine (I can see it logged in on the mini), but screen sharing from the MBP says "reconnecting" and can't connect anymore.
    Something about being logged in on the mini prevents me from sharing its screen.
    I tried creating a new user account without success. I could log into the new account, but as I was logging it, I got the "reconnecting" screen on the MBP (but could see that the login worked on the mini).
    I've got all the right users in the screen sharing part of sharing settings.
    Any ideas?

    have you tried the obvious - restarting the computers involved and the router?

  • IChat AV screen sharing display size limit?

    My machine OSX 10.5.1, iChat 4.0 on 17in Powerbook; other machine OSX 10.5.1, iChat 4.0 on Macbook Pro WITH 20in Cinema Display connected as 2nd desktop. Connection is Jabber via an OSX 10.4.11 Server and is 'long-range' in the sense of being via the internet, not down the hall.
    Sharing my Powerbook's screen works fine. Sharing the other way around hangs at 'Starting Screen Sharing'. However, if I reduce the resolution of the Cinema display by a few notches it works.
    Screen sharing (i.e. the vnc://...) works both ways without messing with the resolution.
    I'm trying to make this work as a support service for my clients, many of whom have this dual-display setup. I can't use Screen Sharing because the users are behind NAT.
    Is there a known limit in the size of desktop iChat can share? And why would it be different from Screen Sharing? Any ideas gratefully received.

    I have seen the screen shared display at different sizes on my Apple Cinema 17". (will be 5 years old on 22nd Jan)
    As far as I could tell the differences were/are based on the Screen resolution at the far end.
    As both methods are based on Apple Remote Desktop it would seem strange that there would be a difference.
    I would say by casual observation that iChat's version does seem somehow to be more screen intensive.
    My G4 connected to the 17" screen shows the MacBook Pro 15" display at full height and width (Less menu bar and DOCK) with VNC.
    Some strange quirk is preventing me from doing it with iChat right now.
    Does seem odd.
    I have tried playing with the resolutions on both to see if it will work over Bonjour but no luck.
    10:18 PM Monday; January 14, 2008

  • Screen Sharing using Peer to Peer.

    Hi,
    I'm working on a tool, in which i have to implement screen sharing between two users. I have captured my desktop using screen capturer driver. That driver returns byte array of bitmap.
    My question is : I have to send that byte array to other user and convert that byte array into bitmap and show him my desktop. If someone have any idea about how to send byte array using peer to peer and how to use it.
    Please share.

    you can probably just send it as a variable without needing to serialize it.

  • How secure is screen sharing?

    Hi: I have set up my MacPro 2008 to accept screen sharing for one user (me) and I access it from my MacBook Pro via airport/AP extreme (protected by WPA2 Personal) and built-in VNC. Everything works perfectly fine and just as smooth as can be expected from a Mac. My only concern is, whether the connection is safe enough such that my passwords cannot easily be intercepted, or if I need to set up an SSH connection. Any suggestions?
    Thanks.

    WPA2 offers its own encryption, so it's basically secure against anyone not on your LAN so long as they don't have (or break) you WPA2 encryption key.
    That said, you might presume that someone has breached the WPA2 encryption or otherwise gained access to your LAN, in which case the VNC login (and frame buffer data) isn't secure. In that case, what you want is to setup SSH and use the Mac firewall tools to block access to VNC from any host other than localhost.

  • Per-user screen sharing?

    I'm interested in setting up a server system to which different users on different computers can connect and have individual workspaces.  I understand this "per-user screen sharing" feature is not active in Lion, is that correct?  Also I have not discovered information about the capability in Lion Server, can anyone shed any light on this please?
    Thanks very much.
    Peter

    The Apple provided feature set will likely disappoint you.  Look at AquaConnect if you are trying to recreate Terminal Service.

  • Is it possible for multiple users to use a "generic" account simultaneously without screen sharing?

    Hey and thanks for checking out the thread.
    I am wondering if it is possible to have users use a generic account at the same time without any sort of screen sharing.
    I have set up a generic user account (for example useraccount, password 1234) for users to use in the time before I can set up a custom user name for them. However, I have run into some issues with this.
    When multiple users log on using this generic account, their applications seem to be shared on each screen. In the room with multiple Mac workstations, if someone starts working on Photoshop, Photoshop will open on every one elses screen who is logged on under that generic account.
    Is it possible for users to log on using a generic network account and have their own isolated work environment or is this sort of sharing a feature? I am new to Mac servers and am not sure.
    Thanks for reading the thread.

    That shared-account approach seems impractical for the various reasons you've identified, as well as the inevitable issue of cleaning up the detritus that'll inevitably build up in a shared account, and for the lack of accountability for activities occuring under the shared account for both auditing and security, and sharing directories would tend to introduce obscure conflicts around which-file-version-wins file updates when the same file is used in several places, and would probably be contrary to any per-user application software licensing agreements that might be involved.
    Put another way, get unique accounts created for folks, and work toward the ability to create accounts for arriving folks, and — if it's applicable here — talk to management about getting any per-user software licensing issues sorted out, whether that's having spare copies purchased and ahead or some advanced notice on accounts, or establishing group software licensing where that's available.
    AFAIK, there are tools around which can automate account creation, too.  Either generic, a tool such as Passenger, or it's certainly feasible to script the account creation sequence.
    Trying this shared-access generic-account approach just looks like it can create more work and more hassles and more effort to me...

  • How to disable 'select display' on screen sharing?

    One improvement in Lion is Screen Sharings 'asking' of the current logged in user as to whether or not it is ok to share the screen.  While I understand the need for this in a multi-user environment, this is a unnecessary level of feature for most home users.  In fact, it's been a total pain and I'd like to know how to disable it.  Trying to remote support parents has become virtually impossible as they are unsure as to what it means to allow screen sharing when I attempt to connect.
    Anyone know how to disable this feaute and let Screen Sharing work as it did pre-lion?

    Apple menu > System Preferences > Sharing > Screen Sharing > Allow access for: account you want to log into
    Connect as that user.

  • Disable USB per USER

    Hi guys,
    i really need your help to disable USB per User. I have installed Windows WMS 2012 on a server and it is connected with USB to LG monitors, my issue is i have to disable USB devices per Monitor. Can anyone help me it is very urgent !!!
    Kind Regards,

    The easiest way is to set the permissions on the
    printer utility for only the Admin account.
    Go to the Applications\Utilities\Printer Utility.
    Getinfo on the Printer Utility and set the "others"
    to No Access.
    Be sure to remove the printer(s) from the accounts
    you don't want to have printing. This is a global
    change and there won't be any printers available
    under the users account. This will prevent (Kids)
    users from adding a printer.
    I just tried this and I could not get it to work for me. I changed the access on Printer Setup Utility and removed the proxy printers (~/Library/Printers) and all .plist files having to do with printing (~/Library/Preferences) from a non-administrative user account. I was still able to print from Word without any problems.
    Also, when I Repaired Permissions, the permissions for the Printer Setup Utility returned to "factory specs" and "Others" again had Read permission.
    Did I misinterpret your instructions?
    Matt

Maybe you are looking for