is there a way to let terminal services make some kind of 'abstraction' over the physical network interfaces of the server so they can be managed via gpo to grant or prohibit access for different users?
the basic idea is to have 2 network interfaces (user and server/management) and not letting users within terminal sessions access the server/management network.
or is this just impossible ? what would be a better way to do this ?