Note: this set of GPOs accompany's a YouTube video all about building your own pentest lab
Personally, when I setup an internal/test/pentest Active Directory environment I like to leave some settings the way most client environments are setup - both for ease of management and easier attacks, so that includes spinning up the following GPOs:
Enable RDP on desktops
Create a new GPO and link it whatever OU your workstations are in, and set Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Connections and set Allow users to connect remotely using Remote Desktop Services to Enable
Then, create a security group in AD, called RDP-peeps for example, that you want to allow to RDP into all workstations.