Remote management through Windows Server Terminal Services

  

The servers of the authors are stored in a relatively independent computer room. If you need to go to the computer room every time you go to maintain the server, it is not a hassle to die. The author is now implementing remote management of the server through the terminal service of the Microsoft server. The author connects to the terminal service on the server through the client connection software. After authenticating, the author's native desktop will display the server's desktop. And I can execute applications, storage files, and network resources on the server on my desktop. Except for the slight effect of speed, it is similar to the operation on this unit.

First, the essence of the terminal server.

When I connect to the terminal server through the network, I need to run some programs on the server. In fact, these applications are executed on the terminal server, not on the local machine. In other words, the author's computer functions like a keyboard and a mouse. That is, the author only operates the application through his keyboard and mouse on his computer, and then displays the results transmitted by the terminal server on the screen.

And through terminal services, multiple people can manage the server at the same time. For example, application services such as mail service and database service are deployed on the server of Microsoft. At this point, the mail administrator, database administrator, server administrator, etc. can simultaneously connect to the server and execute the application located in the terminal server.

So Terminal Services is a very useful tool for enterprise network administrators. In particular, the enterprise network is relatively large in scale and has relatively independent computer rooms. At this point, it is not convenient for the administrator to go to the front of the server for maintenance. The administrator is the most convenient way to maintain the server remotely.

Second, the remote control access control.

Although remote connections provide great convenience for network administrators. However, it is also likely to bring certain security risks to the server. To this end, the network administrator needs to pay attention to the security of the terminal service while facilitating the daily work. Microsoft Terminal Server has also taken some measures in security. To allow a network administrator to manage a server through Terminal Services, two prerequisites must be met. One is to start the remote desktop function on the server, and the other is to add the user account to the remote desktop user group. These two are the conditions necessary for the network administrator to connect to the server.

The method of adding users to the remote desktop user group depends on the specific configuration of this server. The server's related service configuration is different, and the method of setting it is different. In general, there are the following.

First, if the terminal server is not installed on the server and only the remote desktop management is started, the network administrator can also remotely manage through the terminal service. That is, Remote Desktop is a simplified version of Terminal Services. At this point, if you want to add users to the remote desktop user group, you can do so by following the steps below. The network administrator can select Start, Settings, Control Panel, System. Select the "Remote" tab in the dialog that opens and select the "Allow users to connect to this computer remotely" checkbox to initiate the remote connection. Then click the "Select Remote User" button to join the user to the Remote Desktop User Group. As shown below:


For security reasons, it is best to configure the relevant security policy for this account. For example, the password policy can be used to enforce the complexity of the password; the login time event of this account can be audited; and the function of automatically locking the account when the password is entered incorrectly more than three times is set. These measures are taken to ensure the security of the username and password; thus ensuring the security of remote maintenance.

Second, the server is deployed with a terminal server, and this server is relatively complex in configuration in the Microsoft domain environment, but its security will be higher. At this point, the network administrator also needs to enable the remote desktop function first. At this point, the network administrator can also select "Start", "Settings", "Control Panel", "System". Select the "Remote" tab in the dialog that opens and select the "Allow users to connect to this computer remotely" checkbox to initiate the remote connection. However, there are differences when configuring an account.

Previous 12 Next Read more

Copyright © Windows knowledge All Rights Reserved