Locking down a single server

J

Joe C

Greetings! I am currently working on a project to set up a single Citrix
server for our company (running windows 2000 server and on our domain -
only one domain). I would like to set up a policy that does things such
as hide local drives (so people aren't cluttering up or saving documents
locally), disable access to the control panel, etc.

However, this policy should only affect users when they log onto this one
server and not when they are logged into their own workstations. Also,
the only user who should be exempt from this policy and thus have total
access would be the domain Administrator account.

Would the best way to do this be to set up a local policy as in
http://www.jsiinc.com/sube/tip2400/rh2492.htm? Or should I create an OU,
place this one computer in the OU and apply a GPO? If so, how should I
set it up so that the policy affects everyone except the Administrator
account?

I'm rather new to setting up GPO and appreciate any assistance!

Thanks in advance,

Joe
 
S

Steven L Umbach

You would want to use "loopback processing" of Group Policy. Put that computer in
it's own OU and configure user policy as the way you want it for that OU and then
configure loopback processing [probably replace] in the computer configuration
section. I am not 100 percent about this part [with using loopback processing], but
normally you "filter" a GPO to include or exempt users/groups. In this case try
filtering the GPO for that OU to deny apply to the administrators group. See the
links below for more information and test out before rolling out. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;231287
http://support.microsoft.com/default.aspx?scid=kb;en-us;322176 --- see part on
filtering
http://www.microsoft.com/resources/...erver/reskit/en-us/distsys/part4/dsgch22.mspx
--- general info
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top