5.117 - Users must be prevented from connecting using Terminal Services.

Information

Allowing a Terminal Services session to a workstation enables another avenue of access that could be exploited. The system must be configured to prevent users from connecting to a computer using Terminal Services.

Solution

Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Terminal Services -> Terminal Server -> Connections 'Allow users to connect remotely using Terminal Services' to 'Disabled.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip