Enable loopback processing in GPO linked to the OU containing the TS computer object.
Computer Configuration\Policies\Adm
When loopback processing is enabled, you can link GPOs with user configuration settings to the OU containing the TS computer object. Use security filtering on the GPO to restrict it from affecting administrator by configuring the 'apply group policy' permission for the GPO.
Enable and configure the following policy settings in a GPO linked to OU containing TS computer object to hide or prevent access to some drives
User Configuration\Policies\Adm
- Hide these specified drives in My Computer
- Prevent access to drives in My Computer
If there's other drives than the default values that nead to be handled in the policy, you can modify the available options by following this KB
http://support.microsoft.c
See this KB for policy settings that can be used to restrict non-admins on a TS
http://support.microsoft.c
Main Topics
Browse All Topics





by: tronics80Posted on 2009-10-14 at 16:11:42ID: 25576105
To be more concret:
How to add a user that can user Remote Desktop for Webbrowsing and WinSCP?
How to lock that user in his homedirectory, so he cannot change and see contents in additional NTFS harddrives?
Active directory is available.
Thank you