Set logon hours for security groups that will access RDS 2012

Hi All,
We have the following hardware for our RD Web solution:
1 Server – RD Gateway, RD Licensing, RD Web Access, RD Connection Broker
1 Server – RD Session Host 1
1 Server – RD Session Host 2
Our environment consists of the following:
1 Windows Server 2012 R2 domain controller at the main office, 4 additional 2003 R2 domain controllers scattered
throughout our 4 remote offices. Domain functional level of 2003. This all works under one flat domain called  company.business.com
We have RDS up and running, and all of our users are able to access it through the internet either from home or  directly from their remote office. Our next step is to focus on restricting
access.
In Active Directory, we have accounts for Support Staff, and accounts for Sales People. They will all have access to RDS in
the following ways:
Support Staff will use it from 8am to 5pm throughout the day so that they may connect to the Mickey Mouse 2000 software that is located in the main office
Sales People will use it 24/7 for all intended purposes
How do we set it so that Support Staff can only access it internally but not externally when they are outside of the
office while still providing 24/7 access to the Sales People?
Can this be accomplished using security groups or logon hours? All input is greatly appreciated, thank you!

Hi,
Thank you for posting in Windows Server Forum.
Based on your description seems you want to have user to get access your software by RemoteApp. You can achieve your desired solution with below steps.
• Support Staff will use it from 8am to 5pm throughout the day so that they may connect to the Mickey Mouse 2000 software that is located in the main office
• Sales People will use it 24/7 for all intended purposes
For above one, you can restrict the access to particular user\group from the “ADUC>Users properties>Account>Logon Hours” where need to specify the time limit for user to Logon or denied logon.
How do we set it so that Support Staff can only access it internally but not externally when they are outside of the office while still providing 24/7 access to the Sales People?
When you have setup your environment, you have configured RD RAP and RD CAP; right? You can try not to include the user group that you don’t want to have outside environment. Please check following article for information.
Checklist: Make RemoteApp Programs Available from the Internet
http://technet.microsoft.com/en-in/library/cc772415.aspx
Hope it helps!
Thanks.
Dharmesh Solanki
TechNet Community Support
Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

Similar Messages

  • Do I need rtexprvalue set to true for a String that will vary from page to page?

    Hi I am a newbie to JSP tags. I have done enough reading so far to see
              that if I want an attribute of the tag to be a scriplet ie:
              <foor:bar name="<%=myObj.getName()%>" />
              then the rtexprvalue for this attribute in the TLD needs to be true.
              My question is what if I have an attribute that will not be read from
              a scriplet but will vary from page to page. ie:
              <foo:authorize securityLevel="1"> but on another page it will be
              <foo:authorize securityLevel="3"> etc.. Since many servlet containers
              create only one instance of the tag class and then re-use them from a
              pool do I need to set rtexprvalue to true for an attribute like this
              to make sure the tag reads the correct one as I go from page to page?
              

              You do not need to set rtexprvalue to true for the situation you describe.
              Laura
              Developer Relations Engineer
              BEA Support
              [email protected] (Mike Lomage) wrote:
              >Hi I am a newbie to JSP tags. I have done enough reading so far to see
              >that if I want an attribute of the tag to be a scriplet ie:
              > <foor:bar name="<%=myObj.getName()%>" />
              >then the rtexprvalue for this attribute in the TLD needs to be true.
              >My question is what if I have an attribute that will not be read from
              >a scriplet but will vary from page to page. ie:
              > <foo:authorize securityLevel="1"> but on another page it will be
              > <foo:authorize securityLevel="3"> etc.. Since many servlet containers
              >create only one instance of the tag class and then re-use them from a
              >pool do I need to set rtexprvalue to true for an attribute like this
              >to make sure the tag reads the correct one as I go from page to page?
              

  • Tabs: previous versions allowed for saving all tabs in a bookmark folder. The new tab groups do not behave this way. How can I save permanent set of tabs as a group that is available later, like the folder of bookmars was?

    tabs: previous versions of firefox allowed for saving all tabs with a group name, so you could open them all again later at your convenience. The new firefox 4.0.1 has a new tab feature, but the tab groups do not seem to persist once you shut down, and are not saved as a folder in your bookmarks. What am I missing? How can I do what I want (save permanent set of tabs as a group that is available later, like the folder of bookmarks was)? Thanks

    Right click one of the tabs, the "Bookmark all tabs..." option.
    Does it do what you want?

  • HT5312 why can't I sign into my account and add a rescue email so I will be able to redo my security questions? I have been unable to buy anything from Itunes because it's asks me for security questions that I don't remember what I put

    why can't I sign into my account and add a rescue email so I will be able to redo my security questions? I have been unable to buy anything from Itunes because it's asks me for security questions that I don't remember what I put in the first place

    1. Because if you could, someone who breaks into your account could do it as well.
    2. You need to ask Apple to reset your security questions; ways of contacting them include clicking here and picking a method for your country, phoning AppleCare and asking for the Account Security team, and filling out and submitting this form.
    (96882)

  • Is there a DJ app for the Ipad that will read the "start" and "stop time" setting for each individual song, as they are set in the song Options screen in Itunes?

    Is there a DJ app for the Ipad that will read the "start" and "stop time" setting for each individual song, as they are set in the song Options screen in Itunes? The Ipod Touch, by itself does not allow cross-fading, therefore when the stop time is edited short, the song jusst truncates then goes to the next song. I tried the DJay ap and while it would crossfade, it would NOT read the song settings for the stop marker. So now I want to try and Ipad and see if there is an app that will READ the Itune stop settings within the song. I do NOT want an app that will allow me to DO the stop marker. I want an app that will READ the stop marker from the song as it is set in Itunes.

    Itunes provides the option for setting the Start and Stop times of each music track.  However, the start and stop times do not synchronize to the iPhone.  I don't understand why this option is even available as it doesn't work when listening to music on the phone.  I have not found another application that will support the start and stop time markets.  I have searched quite a bit for this but can't find anything.  I hope we can find something. 

  • HT201359 I purchased a audio book to listen to on my commute to work. It only works over wifi, that does me no good in the car and the book is hours long for audio. That will eat up my data. How can I get a refund?

    I purchased a audio book to listen to on my commute to work. It only works over wifi, that does me no good in the car and the book is hours long for audio. That will eat up my data. How can I get a refund?

    How are you trying to listen to it ? You shouldn't need to be online to listen to it, I don't for any of mine. If you've downloaded it directly on your iPad (or synced it from your computer) then it should be in the Music app (you will get an Audiobooks option under the More button in the Music app when you have audiobooks on it) - is that where you are trying to listen to it ?

  • What is the best compressor setting to use ... when exporting a 720p timeline from FCP for a project that will only be played back in a standard def monitor?

    What is the best compressor setting to use for DVD StudioPro ... when exporting a 720p 30 timeline from FCP for a project that will only be viewed in a standard def monitor?

    Update: The iBook can play any 480p video and higher if I encode them with DivX and in AVI format. But of course this is not compatible with my iPhone 4. At least I can shrink my library now and get away from the full MPEG-2s. I don't get why I can't use Apple's h264 though. There has to be a setting I am missing. The sample Apple h264 videos from the days of Tiger worked flawlessly on my iBook when it was new so the CPU must be capable of decoding it. I really can't understand this.
    Also, since I made my videos in English for my family, I had to create soft subtitles for my wife's Chinese family, and I can't get players like QT with perian or MPlayerX to sync them properly to an AVI encoded with DivX, they only sync well with the iPhone 4 m4v/mp4 formatted files I made. This is a real pickle.
    So now I may need three or four copies of each video, LOL. I need to hardcode the subtitles if I want to use AVI to playback on older machines, and keep the mp4 file for the iDevices too, while keeping higher quality h264 videos for my American relatives...
    If h264 is compatible with my iBook, what is the proper encoding settings? Must I dramatically lower the settings or frame rate? I can settle on 2 copies of each video that way. One iBook/G4/eMac compatible video that syncs correctly with my srt soft subs, and another version that works well with my iPhone 4 and iPad.
    All in all, I will end up with more than 3 or 4 version of each video. On my late G5 dual core I have the full 720-1080p uncompressed master files. On my i5 iMac I have the h264 compressed versions for distribution, and lower versions for my iDevices. Now I need to keep either full MPEG-2 files for the iBook to play, or convert to older formats like DivX AVI for our family's legacy machines. I am running out of hard disk space quick now, LOL.
    Is there an easier way?

  • I'm looking for an app that will allow a presenter to give ipads to several other users in a room and control what's on display for the group

    please let me know if you know of any good apps to sync up several ipads in a room with one person in control. I'm looking for an app that will allow a presenter to control what's on display for several other ipad users in a room. I'd like to be able to do presentations over the ipad, but i want the presenter to control the screens so folks in the meetings don't get distracted by playing with the ipad. i'd like to avoid using a web meeting service and do this without having to connect to any kind of network since i'll often be doing this outside of my office.

    Try http://mysyncpad.com/. I'm not sure if it will do all you need, but it's the closest I've seen.

  • Users assigned directly to a SharePoint group can access a site if a user is in a security group that is a member of the SharePoint group, it doesn't work

    I recently installed SharePoint 2013 SP1 and thus far all seems to be going well. I do have one issue concerning permissions to a team site I have created:
    1. If  add a user User1 only to a SharePoint group that has edit permissions to the site, that user can log in successfully.
    2. If  add a user User1 only to a security group that is a member of the aforementioned SharePoint group, the  user gets "the site has not been shared with you. The security group is a global SG, though I tried changing it to universal 
    but that did not help
     I have tried updating the SPSecurityTokenServiceConfig  as briefly described at this link:
    http://macaalay.com/2014/05/27/active-directory-groups-and-access-denied-in-sharepoint-2013/.  I performed the steps and it did not work. I also
    tried rebooting the server after that, and that did not work either.  any thoughts?
    Thanks in advance for your help

    Hi,
    I tested the issue on SharePoint server 2013 without sp installed. It worked and I used global security group. I will test the issue on SharePoint 2013 sp1 later, and please provide more information to narrow down the issue.
    Please go to site settings > site permissions > check permission, type in domain\user1, and post the result here.
    If the user has been granted permission, please try logging on another machine to test if Windows credential casues the issue.
    Did the issue occur to one site collection? Please test on other sites or web applications?
    Please create new user to test the issue again.
    Regards,
    Rebecca Tu
    TechNet Community Support

  • My DVR security sofware that I access remotely uses a "dvr .ocx" file....when I try it in Firefox , either the latest non beta (3.6.1.5) or the new beta version (4.0 rc) it will NOT work as it says the plugin is missing... it works in IE 8,but not IE9...

    My machine is Top of the range (my Company builds them so it had better be :) )
    Amd 1100t , 8gb ram , Windows 7 64 bit etc, etc...
    The is not a hardware problem , but a software problem with FF...Any help would be appreciated as I hate using IE 8 for anything at all :( but I have to keep it on my machines just to run my remote security cameras at my Computer shop ???
    Original question...as question length is limited ...not very bright that limit by the way :(
    "My DVR security sofware that I access remotely uses a "dvr .ocx" file....when I try it in Firefox , either the latest non beta (3.6.1.5) or the new beta version (4.0 rc) it will NOT work as it says the plugin is missing... it works in IE 8 (unfortunately) but not IE9...
    As I own a Computer company I am fairly computer literate but cannot find a plugin that allows this to work in Firefox.... but I would have expected it to work in the new Firefox :(
    All the best, Brett :)

    The longer this thread continues, the more ancillary comments you throw in that aren't directly pertinent to your problem with your DVR software not working with Firefox 4.0. Sorry, I don't intend to continue with this discussion.
    I do agree that ''something'' needs to be done better with regards to plugins for Firefox, but I do disagree with you as to whose responsibility that ''something'' is.

  • Is there an app for the ipad that will allow you to access your mac.

    Is there an app for the ipad that will allow you to access your mac via wifi or cell network.

    Yep, two of the most popular apps are "LogMeIn Ignition" and "iTeleport." Check them out, they'll both set you back by about 30$ though.

  • What is the maximum number of contacts in a group that will send in an iCloud email? I'm sending from MacBookPro.

    What is the maximum number of contacts in a group that will send in an iCloud email? I'm sending from MacBookPro.

    Limits on Sending Messages  
    iCloud has several safeguards to ensure that only iCloud members can send messages using the iCloud outgoing mail server. Among these safeguards are reasonable limitations on:
    The total number of messages you can send each day (200 messages)
    The number of recipients to whom you can send each day (1000 recipients)
    The maximum number of recipients per message (100 recipients)
    The size of incoming and outgoing messages (20 MB)
    You can send 10 emails to 100 people each in a day, for example, or 198 messages with, on average, 5 recipients (and five ninety-ninths).

  • What is the Behavior.Navigation URL for creating navigation bar links for search scopes for security group and distribution groups?

    ...the search scope is used to subset the SGs and DGs. The search scope itself shows expected results. The search scope filter used is: /Group[Type='Security' or Type='MailEnabledSecurity'][(Domain = 'DomainX') or (Domain = 'DomainY')]
    Tried the following, with the GUID being the resource ID from the search scope for security groups:
    ~/identitymanagement/aspx/customized/CustomizedObjects.aspx?type=Group&searchtype=e8ed98b6-e299-4b8d-bfe5-e4b2adf1cd60
    ~/IdentityManagement/aspx/groups/Groups.aspx?type=Group&searchtype=e8ed98b6-e299-4b8d-bfe5-e4b2adf1cd60
    Thanks

    are you talking about redirect URL in search scope ? FIM will automatically add the searchtype querystring
    for custom groups search scope you can use :
    ~/IdentityManagement/aspx/groups/AllGroups.aspx
    and configure you search scope to use the same UsageKeywords as for the security groups
    and restart your IIS server using the command "IISRESET"
    in your case if you want to create navigation bar link to your group-type search scope use may use this format:
    http://{your fim server}/IdentityManagement/aspx/groups/AllGroups.aspx?searchtype={your searchscope guid}&content=%2a
    ex : http://fimserver/IdentityManagement/aspx/groups/AllGroups.aspx?searchtype=47e0a973-0ab4-46f5-815f-f5028c1af58e&content=%2a

  • How will the Time Capsule support IPv6 and coop with the new emerging security threats that will emerge due to the new technical possibilities that IPv6 provide?

    How will the Time Capsule support IPv6 and coop with the new emerging security threats that will emerge due to the new technical possibilities that IPv6 provide?

    Cross your fingers and hope.
    Obviously if there is any big or known threat Apple will send out a firmware fix.
    But the TC is designed to be end user simple device. It has no firewall that is visible at any rate. I don't know that it truly doesn't have a firewall but it is not part of the end user controls.
    IMO if you have major security concerns that go beyond end device firewall, which is where Apple do put most of the security, since firewall in the router is plainly not a stop to anybody deliberately downloading an infected file or website, and most end users.. do not want a firewall that prevents them using the web like a business does, where only certain ports are allowed. Everything else tough luck.. you are not allowed to use it. Then TC is unsuitable for you anyway.. buy a proper firewall appliance.

  • How can I set a password for firefox so that everyone have to enter the password before executing firefox

    My younger sister executed my firefox just at this afternoon(she originally use IE), and she saw something that can't be seen. How can I set a password for firefox so that everyone have to enter the password before executing firefox?

    Also see this for an English version of Profile Password:
    *Profile Password: http://nic-nac-project.de/~kaosmos/profilepassword-en.html#PPF
    It is an extension to protect the profile with a password, but being an extension that protection can easily be bypassed by starting Firefox in [[Safe mode]].<br />
    So do not rely on it.<br />
    If you want to protect content then you have to use methods supported by the OS like a separate user account with a password or an encrypted file system.

Maybe you are looking for