Ask a question

User

WseRemoteAccessUsers and WseRemoteWebAccessUsers groups populated...how?

I've reached the point in my migration where I've set up a WSE2016 server, and installed the connector software on most domain computers. 

I noticed in my AD a bunch of new Security Groups created by the WSE2016 server. Two of them are WseRemoteAccessUsers and WseRemoteWebAccessUsers, and both of them are populated with EVERY user object in my AD, regardless of which OU it's in.

I don't think this is a good idea, since some of those user objects are for managed service accounts, disabled accounts associated with Resource Mailboxes, and other special-purpose user objects. Many of them don't reflect an actual human who would use Anywhere Access (either VPN or Remote Web Access). We have 50 employees, but because of all those extra user objects, both those groups have a total of 135 members in them. 

Service accounts are used for a specific purpose, and that purpose does NOT include needing to, or being able to, log into the RWA or VPN services offered by WSE2016. I can remove the unwanted user objects from those security groups, but I never added them to those groups to begin with. So I expect that whatever process added them in the first place will just do so again if I remove them.

Enabling those remote access features on accounts that don't need them just increases the attack surface of the network and server while providing NO benefit to the organization.

Can Mariette or someone else provide more background about the functioning and purpose of these groups, and any best practices surrounding them? Google hasn't found me anything useful yet, though I'll keep looking.

Thanks,

Bryan


asked01/29/2020 22:15
953 views
Add Comment
User

Anyone? I'm always curious when I see people viewing the question, but no answers. Surely I can't be the first person to wonder this. 

I've spent more time playing with those two groups. I decided to manually remove everything in them and explicitly add the existing security groups I already have my users organized into, based on their job role.

I'm going to watch this setup for a while to see whether anything on the WSE server changes or repopulates those security groups in any way. Then I'm going to watch what happens the next time I have to create a new user in our organization, which I will be doing soon due to a new hire coming on board soon. 

Whether anyone else responds here, I'll post back my results from playing with this for the benefit of the community. 

Bryan

Last Activity 01/31/2020 18:36

No answers found

Add an Answer