Windows 2000 Terminal Services usually runs flawlessly and requires practically no administration, so it’s easy to forget that you can make adjustments to it. But with a few simple tweaks, you can get things running even better. To do this, you'll need to use the Terminal Services Configuration tool, a handy interface that allows you to adjust the connections and server settings to meet the needs of your organization.
Running Terminal Services Configuration tool
As with the familiar Terminal Services Manager, you can access the Terminal Services Configuration tool from the Administrative Tools menu. When the tool loads, the screen is deceptively simple. It consists of a standard Microsoft Management Console interface with only two objects, Connections and Server Settings. However, the two tree choices beneath these objects are all you need to make Terminal Services run in the manner that you want them to.
When you select the Connections object under the Terminal Services Configuration root, the available connections will appear in the pane to the right, as shown in Figure A. From here, you can add another connection, delete the existing connection, or modify the existing connection.
The available connections appear in the right pane.
If you want to create a new connection, select the Connections object and then select the Create New Connection command from the console’s Action menu. If you need to delete the connection, right-click the connection and select Delete from the context menu. Note that deleting a connection drops users who are connected to Terminal Services through that connection.
When you right-click on a connection, you will notice one of the choices on the context menu is All Tasks. This menu option includes a submenu, which allows you to either disable the connection or rename the connection. Disabling the connection allows you to temporarily take the connection offline without having to re-create it. Microsoft recommends disabling connections anytime you’re installing new applications on the server.
You can also rename a connection. Of course, renaming a connection allows you to assign the connection a more descriptive name. This can be useful to help you remember exactly why you created the connection in the first place.
Now that you know how to create, delete, rename, and disable Terminal Services connections, let’s take a look at how you can go about modifying a connection. First, right-click the connection and select Properties from the context menu to view the connection’s properties sheet. As you can see in Figure B, this sheet contains several tabs for reconfiguring the connection.
The connection's properties sheet contains tabs that you can use to reconfigure the connection.
The General tab
The General tab allows you to add a comment to the connector’s name. You can also use it to tell Terminal Services to use standard Windows authentication and to set the encryption level. By default, the encryption level is set to Medium, but you can change it to Low for better performance or to High for better security.
The Logon Settings tab
The Logon Settings tab gives you the choice of either asking clients for a login name and password or forcing clients to always use a common user name and password. If you want users to supply their own credentials, select the Use Client-Provided Logon Information radio button. However, this isn’t a very secure solution. You may be better off selecting the Always Use The Following Logon Information option. This will allow specific control over who can access Terminal Services and what they can do.
The Sessions tab
Terminal Services permissions are usually applied on a per-user basis. However, you can use the Sessions tab to override many of the per-user settings and force Terminal Services to behave the same way for every user. For example, you can assign the same time-out settings for everyone and control how Terminal Services handles reconnect requests.
The Environment tab
I’ve always found the Environment tab to be extremely useful. Rather than grant Terminal Services users full access to a Windows desktop, you can completely bypass the user’s normal profile and force Windows to run a specific program when the user connects. This program could be a login script, an application, and so forth. The Environment tab also contains an option to disable the Windows wallpaper, which may enhance performance.
The Remote Control tab
When people think of remote control in the context of Terminal Services, they think of remote server administration. However, this tab controls whether Terminal Services will allow an administrator to take control of a client’s session. You can implement several levels of control.
For starters, you can disallow or allow remote control, and you can place some restrictions on the remote control functions. For example, you can limit the remote control capabilities to allow the administrator to observe a remote session but not to override it. You can also require that the user give the administrator permission to view or control the session.
Remote control can be an especially useful tool for help desk personnel. With remote capabilities, your help desk staff can fix complex problems from their desks. However, even in the hands of an administrator, remote control can be used for unethical purposes, such as invading the privacy of users and watching what they’re doing on their workstations.
The Client Settings tab
The Client Settings tab allows you to determine which external devices are associated with the user’s session. For example, you could map network drives, printers, and COM ports, just to name a few.
The Network Adapter tab
The Network Adapter tab contains a list of all of the network adapters associated with the connection. For each adapter, you can set the maximum number of allowed sessions.
The Permissions tab
From the Permissions tab, you can determine which user accounts have what level of access through Terminal Services. You can specify Full Control, User Access, Guest Access, or any combination of individual permissions.
Now, let’s take a look at the tool’s other object, Server Settings. As you can see in Figure C, this object offers fewer options than the Connections object. Its settings control the behavior of Terminal Services as a whole rather than the behavior of one individual connection in the way that the Connection object’s settings do.
The Server Settings object's settings control the behavior of Terminal Services.
You’ll first encounter the Terminal Server Mode, which is actually a display-only field. It tells you if the terminal server you’re looking at is set up to allow Terminal Server clients to use it (Application Server Mode) or if the server is simply configured for remote administration. If you need to change the Terminal Server Mode, use the Add/Remove Programs icon in Control Panel to uninstall and then reinstall Terminal Services.
The next setting is Delete Temporary Folders On Exit. Setting this parameter to Yes prevents files related to individual terminal sessions from filling up your server’s hard disk.
The next setting is Use Temporary Folders Per Session. I recommend setting this option to Yes to keep each group of temporary files isolated to the session using them. This makes for a much easier cleanup after the session ends. If a tidy cleanup isn’t enough of a reason for you to enable this setting, consider this: If you don’t use a separate set of temporary files for each session, it’s theoretically possible that a change made by one user could affect all other sessions. That’s bad security.
If you service clients with your Terminal Server (other than remote administration sessions), you must purchase client access licenses for each non-Windows 2000 Professional seat that will be using Terminal Services. The next setting, the Internet Connector Licensing, is separate from this. This setting is actually a license you must purchase if you need to allow Internet users (not employees) to anonymously access your Terminal Server to run Windows-based software.
As you can probably guess, the next setting on the list, Active Desktop, simply enables or disables Active Desktop for your Terminal Server users. Although the Active Desktop is enabled by default, in some cases, you can achieve performance gains by disabling it.
The final list item is Permission Compatibility, which is set by default to Windows 2000 Users. I recommend leaving this setting alone. If you do need to change it, however, Terminal Services must be running in Application Server (not Remote Administration) mode before you’ll be allowed to make the change.
Because of the extremely low level of maintenance required by Terminal Services, it’s easy to forget that you can tweak it to better meet your needs. You can take advantage of the Terminal Services Configuration tool, which Microsoft has made simple to use, to modify the various settings. Once you learn where everything is and what it does, you’ll have little problem tuning Terminal Services for maximum performance.