Back to the basics: Why having Terminal Services and Remote Desktop Services on the Domain Controller is a very bad idea.
Security is a top concern for organizations of all sizes, and it is critical to ensure that sensitive information and systems are protected against threats. One of the key security risks of combining domain controller roles with terminal server roles is the potential for data breaches. In this post, we will examine the security implications of combining these two roles and why it is best to keep them separate. Increased Attack Surface: Terminal servers are designed to provide remote access to users, which makes them a prime target for attackers. When the domain controller role is added to the terminal server, the attack surface is increased, making it easier for attackers to gain access to sensitive information. This can result in unauthorized access to sensitive data, such as user credentials, security policies, and other confidential information stored on the domain controller. Lack of Segmentation: Domain controllers store and manage sensitive…