Solved

Windows 2000 ADS with NT4.0 standalone server with citrix metaframe 1.80 and remote policy issues

Posted on 2004-04-13
6
363 Views
Last Modified: 2013-12-04
3 servers, 1 windows 2000 ADS , 1 Windows 2000 standalone, 1 NT4.0 standalone terminal server enabled and citrix metaframe 1.80 installed; users are logging in by the citrix client.

I have been asked to lock down the nt 4.0 box for the remote users, so basically they will have only 1 published application and access to the printers. I have read other news groups but have not come across a mix 2000/nt 4.0 enviroment for remote user policies.

Any suggestions?
0
Comment
Question by:HynesCo
  • 3
  • 2
6 Comments
 
LVL 12

Expert Comment

by:trywaredk
ID: 10820912
Guide To Windows NT 4.0 Profiles and Policies (Part 4 of 6)
http://support.microsoft.com/default.aspx?scid=kb;EN-US;185589

Many Regards
Jorgen Malmgren
IT-Supervisor
Denmark

:o) Your brain is like a parachute. It works best when it's open
0
 
LVL 1

Author Comment

by:HynesCo
ID: 10823372
Been there, done that, looking for some real world info dealing with Citrix and NT 4.0 policies and issues in a 2000 Active Directory domain.  I apologize if I didn't make that clearer earlier.
0
 
LVL 83

Expert Comment

by:oBdA
ID: 10826449
Are those machine stand-alone or member server? An NT4 machine that's part of a W2k domain will still look for the usual NTConfig.pol in %Logonserver%\netlogon, so you can still use poledit, load the templates you need and create the necessary policies.
Where or what are your concerns?
0
Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

 
LVL 1

Author Comment

by:HynesCo
ID: 10826856
I am getting

The operating system was unable to create profile directory \\servername\path\ntconfig.pds
you will be loged on with the local profile only.

2000 Active directory with  nt 4.0 member servers

My concerns are
I dont want to jack with the ntconfig.pol on the 2000ADS server I only have about 15 remote citrix users
who also logon locally from time to time, the 200+ other accounts are local

so remote users are logging in by a public address that gets forwarded to the nt4.0 server IP not the 2000ADS IP

so on the nt box I used poledit and changed the local computer\system policy update to remote,  created a test.pol and manually tied it to my test user via the terminal server profile path on the local user account.

Am I just way off base here, I am definitly not an expert on policys.







0
 
LVL 83

Accepted Solution

by:
oBdA earned 500 total points
ID: 10827742
You're on the wrong track. System Policies have nothing to do with a (terminal) user's profile path. They're just a bunch of registry manipulations that gets applied when a user logs on.
And there's no need to worry about your W2k DC, the NT4 policies won't apply to it.
If this is just a single Terminal Server, you can even keep the policy file local.
So create a global group and put your TS users in there. Then create an NTConfig.pol file which applies the settings you need to the group you created. Do *not* use the Default User (and try to stay away from the Default Computer as well) for that, or the policies will affect anyone logging on to the machine, including the Administrator. Save the file someplace on your TS, then use the article below to point your TS to it.
You might want to try this on some test machine first, before you create a policy for your production server! For testing the implications and the basic function of this, an NT4 workstation will work. System Policies are very nice if you know how to handle them; but if you're not careful, you can mess up a user's profile badly. That's why you should try to stay away from the computer settings, unless you're sure you know what you're doing. You can delete a user profile, but fixing computer settings can turn out to be messy ...
Note especially that if you enabled a policy at some point, it was applied to some users, and you set it back to "grey", the policy will *not*, I repeat *not* go away (like a W2k Group Policy). The registry setting defined by the policy will simply remain unchanged.

How to Set Up Locally-Based System Policies
http://support.microsoft.com/?kbid=168579

Here's the "real" guide with pictures and everything :)
Guide to MS Windows NT 4.0 Profiles and Policies
http://www.microsoft.com/technet/prodtechnol/winntas/maintain/prof_pol.mspx
0
 
LVL 1

Author Comment

by:HynesCo
ID: 10829113
oBdA,

You da man!
oh yea, the pics did help :)  
0

Featured Post

Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Many people tend to confuse the function of a virus with the one of adware, this misunderstanding of the basic of what each software is and how it operates causes users and organizations to take the wrong security measures that would protect them ag…
No security measures warrant 100% as a "silver bullet". The truth is we also cannot assume anything but a defensive and vigilance posture. Adopt no trust by default and reveal in assumption. Only assume anonymity or invisibility in the reverse. Safe…
This Micro Tutorial will give you a basic overview how to record your screen with Microsoft Expression Encoder. This program is still free and open for the public to download. This will be demonstrated using Microsoft Expression Encoder 4.
Along with being a a promotional video for my three-day Annielytics Dashboard Seminor, this Micro Tutorial is an intro to Google Analytics API data.

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question