• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.

domain users account can log onto windows!

S

sagelike

Guest
I discovered that the domain user that Plesk creates for a domain (xyz.com = "xyz" user) can actually log onto Windows, assuming someone made it that far.

We use other remote control programs to access the server (not RDP) and each access point represents one more barrier to entry. Assuming someone could access remote control, being able to access the server via a user account provides dozens of opportunities to try various user names and passwords and since users don't always create strong passwords, this represents a serious security risk.

Users have limited privileges but they users shouldn't be allowed to logon onto the server directly and I'd like to know how disable Windows server logon without affect access to their server account.

Anyone have any experience with this or advice?

I really want to lock this down.

Thanks
G
 
Go to Domains -> domain name -> Setup and make sure that "Login prohibited" is set in the "Access to system" menu.
 
Hi there

thanks for the answer. I checked and it is turned off however I can still log into windows via remote.

It's highly unlikely anyone would get that far however I like to have that extra bit of assurance that even if they did, they wouldn't be able to do anything, if for instance they somehow managed to grab a user password.
 
Back
Top