Description:
Disables the administrator rights to customize security permissions in the Terminal Services Configuration tool (Tscc.msc).
Use this setting to prevent terminal server administrators from making changes to the security descriptors for user groups in the TSCC Permissions tab. By default, administrators are able to make such changes.
If you enable this setting, the TSCC Permissions tab cannot be used to customize per-connection security descriptors or to change the default security descriptors for an existing group. All of the security descriptors are Read Only.
If you disable this setting or do not configure it, server administrators have full Read/Write privileges to the user security descriptors in the TSCC Permissions tab.
Note that the preferred method of managing user access is by adding a user to the Remote Desktop Users group.