Solved

Windows 2000 ADS with NT4.0 standalone server with citrix metaframe 1.80 and remote policy issues

Posted on 2004-04-13
6
362 Views
Last Modified: 2013-12-04
3 servers, 1 windows 2000 ADS , 1 Windows 2000 standalone, 1 NT4.0 standalone terminal server enabled and citrix metaframe 1.80 installed; users are logging in by the citrix client.

I have been asked to lock down the nt 4.0 box for the remote users, so basically they will have only 1 published application and access to the printers. I have read other news groups but have not come across a mix 2000/nt 4.0 enviroment for remote user policies.

Any suggestions?
0
Comment
Question by:HynesCo
  • 3
  • 2
6 Comments
 
LVL 12

Expert Comment

by:trywaredk
ID: 10820912
Guide To Windows NT 4.0 Profiles and Policies (Part 4 of 6)
http://support.microsoft.com/default.aspx?scid=kb;EN-US;185589

Many Regards
Jorgen Malmgren
IT-Supervisor
Denmark

:o) Your brain is like a parachute. It works best when it's open
0
 
LVL 1

Author Comment

by:HynesCo
ID: 10823372
Been there, done that, looking for some real world info dealing with Citrix and NT 4.0 policies and issues in a 2000 Active Directory domain.  I apologize if I didn't make that clearer earlier.
0
 
LVL 83

Expert Comment

by:oBdA
ID: 10826449
Are those machine stand-alone or member server? An NT4 machine that's part of a W2k domain will still look for the usual NTConfig.pol in %Logonserver%\netlogon, so you can still use poledit, load the templates you need and create the necessary policies.
Where or what are your concerns?
0
Give your grad a cloud of their own!

With up to 8TB of storage, give your favorite graduate their own personal cloud to centralize all their photos, videos and music in one safe place. They can save, sync and share all their stuff, and automatic photo backup helps free up space on their smartphone and tablet.

 
LVL 1

Author Comment

by:HynesCo
ID: 10826856
I am getting

The operating system was unable to create profile directory \\servername\path\ntconfig.pds
you will be loged on with the local profile only.

2000 Active directory with  nt 4.0 member servers

My concerns are
I dont want to jack with the ntconfig.pol on the 2000ADS server I only have about 15 remote citrix users
who also logon locally from time to time, the 200+ other accounts are local

so remote users are logging in by a public address that gets forwarded to the nt4.0 server IP not the 2000ADS IP

so on the nt box I used poledit and changed the local computer\system policy update to remote,  created a test.pol and manually tied it to my test user via the terminal server profile path on the local user account.

Am I just way off base here, I am definitly not an expert on policys.







0
 
LVL 83

Accepted Solution

by:
oBdA earned 500 total points
ID: 10827742
You're on the wrong track. System Policies have nothing to do with a (terminal) user's profile path. They're just a bunch of registry manipulations that gets applied when a user logs on.
And there's no need to worry about your W2k DC, the NT4 policies won't apply to it.
If this is just a single Terminal Server, you can even keep the policy file local.
So create a global group and put your TS users in there. Then create an NTConfig.pol file which applies the settings you need to the group you created. Do *not* use the Default User (and try to stay away from the Default Computer as well) for that, or the policies will affect anyone logging on to the machine, including the Administrator. Save the file someplace on your TS, then use the article below to point your TS to it.
You might want to try this on some test machine first, before you create a policy for your production server! For testing the implications and the basic function of this, an NT4 workstation will work. System Policies are very nice if you know how to handle them; but if you're not careful, you can mess up a user's profile badly. That's why you should try to stay away from the computer settings, unless you're sure you know what you're doing. You can delete a user profile, but fixing computer settings can turn out to be messy ...
Note especially that if you enabled a policy at some point, it was applied to some users, and you set it back to "grey", the policy will *not*, I repeat *not* go away (like a W2k Group Policy). The registry setting defined by the policy will simply remain unchanged.

How to Set Up Locally-Based System Policies
http://support.microsoft.com/?kbid=168579

Here's the "real" guide with pictures and everything :)
Guide to MS Windows NT 4.0 Profiles and Policies
http://www.microsoft.com/technet/prodtechnol/winntas/maintain/prof_pol.mspx
0
 
LVL 1

Author Comment

by:HynesCo
ID: 10829113
oBdA,

You da man!
oh yea, the pics did help :)  
0

Featured Post

Free camera licenses with purchase of My Cloud NAS

Milestone Arcus software is compatible with thousands of industry-leading cameras for added flexibility. Upon installation on your My Cloud NAS, you will receive two (2) camera licenses already enabled in the software. And for a limited time, get additional camera licenses FREE.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In a recent article here at Experts Exchange (http://www.experts-exchange.com/articles/18880/PaperPort-14-in-Windows-10-A-First-Look.html), I discussed my nine-month sandbox testing of the Windows 10 Technical Preview, specifically with respect to r…
Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now