Quiz Entry - updated: 2026.09.29
If the domain group Domain Users is placed in the local Remote Desktop Users group via GPO, who can log on remotely?
Every user account in the domain, on every computer the GPO applies to.
Domain Users automatically contains every user account created in the domain. Putting it into Remote Desktop Users therefore grants RDP logon to all of them at once, not just to the helpdesk or IT.
That is convenient for a test setup, but in production it widens the attack surface considerably: any phished employee account can open desktop sessions on all those machines. A tighter design would put a dedicated group (for example the IT role group) into Remote Desktop Users instead.