problem restricting TS sessions through GPO

D

Drazen

First I created new OU - "Terminal users", put all TS users
in that OU. Then I assigned group policy object to that OU
following article http://support.microsoft.com/default.aspx?scid=kb;en-us;278295
on Microsofts knowledgebase.
The only settings I left out was those computer related and
folder redirection. Then I tried to log in as one of TS users and the
desktop was locked down as it should be. However, after some time
I tried to login again as that user and the desktop was unrestricted!
Then I "touched" the GPO settings (applying the same setting for one
policy as it already had), tried to log in as same user and got locked
down desktop.
And finally after some time I tried to log in as that user and
got unrestricted desktop again :-(

Why is this happening? Also I tried to turn on "Block policy
inheritance".
The user in question has "Domain admin" privileges. Could that
interfere with GPO settings? Everything is happening on w2000 DC.

Drazen
 
C

Cary Shultz [A.D. MVP]

Drazen,

Did you put the actual computer account object in that OU?

Also, if you created a security group that included all of your TS users,
removed the Authenticated Users from the Security tab and replaced it with
that group and you are logging on with a user account that is not a member
of that group then you will naturally not get that restricted locked down
desktop....

I notice in the last line that you are running Terminal Services on a Domain
Controller. Generally not a really good idea to do from a security point of
view. It is doable but not really suggested. If possible I would change
this to a member server......

HTH,

Cary
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top