Terminal Server GPO problem

G

Guest

Hi there
I have a special problem. In a W2k Server farm with AD should be a lockdown for the WTS Server. This policy should only work on this WTS Server and only for Users, not for administrators or Users with administrator rights who logon there. If the User logs on to his workstation the WTS policy shouldn't take place and the user is able to do what he likes
Any Idea
I have tried a lot with AD policys, but I got nothing working this way
Thanks in advance
Tom
 
C

Chriss3

GPOs are applied only to sites, domains, and organizational units. Group
Policy settings affect only the users and the computers that they contain.
Specifically, GPOs are not applied to security groups

How ever you can always filter out who the Group Policy should apply to or
not apply to by change the security permissions of the object, you can
simply deny the policy to the group Administrator, to do so deny read and
apply policy. but you should also think of this when you make your Directory
Design.

Please read the section How to Filter the Scope of Group Policy According to
Security Group Membership in the follow MSKB:

http://support.microsoft.com/default.aspx?scid=kb;en-us;322176#3

--

// Christoffer Andersson

tgoerres said:
Hi there,
I have a special problem. In a W2k Server farm with AD should be a
lockdown for the WTS Server. This policy should only work on this WTS Server
and only for Users, not for administrators or Users with administrator
rights who logon there. If the User logs on to his workstation the WTS
policy shouldn't take place and the user is able to do what he likes.
 
B

Buz [MSFT]

Use Loopback Policy Processing:

231287 Loopback Processing of Group Policy
http://support.microsoft.com/?id=231287

260370 How to Apply Group Policy Objects to Terminal Services Servers
http://support.microsoft.com/?id=260370

278295 How to Lock Down a Windows 2000 Terminal Server Session
http://support.microsoft.com/?id=278295

198771 How to Lock Down Windows NT and Internet Explorer 4.01 Desktop
http://support.microsoft.com/?id=198771

143164 INF: How to Protect Windows NT Desktops in Public Areas
http://support.microsoft.com/?id=143164


Buz Brodin
MCSE NT4 / Win2K
Microsoft Enterprise Domain Support

Get Secure! - www.microsoft.com/security

This posting is provided "as is" with no warranties and confers no rights.

Please do not send e-mail directly to this alias. This alias is for
newsgroup purposes only.




tgoerres said:
Hi there,
I have a special problem. In a W2k Server farm with AD should be a
lockdown for the WTS Server. This policy should only work on this WTS Server
and only for Users, not for administrators or Users with administrator
rights who logon there. If the User logs on to his workstation the WTS
policy shouldn't take place and the user is able to do what he likes.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top