Solved

Does Windows 2000 DC group policy work on Windows server 2003 terminal server

Posted on 2004-09-15
3
189 Views
Last Modified: 2010-04-14
I hope you can help

I have a windows 2000 server DC and 2 windows 2003 servers configured as terminal server.

I have done the following to try to apply a group policy to the 2 windows 2003 servers

To create a new OU for the Terminal Services servers, follow these steps:
On the taskbar, click Start, point to Programs, point to Administrative Tools, and then click Active Directory Users and Computers.
Expand the left pane.
Click domainname.xxx.
On the Action menu, click New, and then click Organizational Unit.
In the Name box, type a name for the Terminal Services server.
Click OK.

The new Terminal Services OU now appears in the list in the left pane and contains no default objects. The Terminal Services servers reside in either the Computers OU or the Domain Controllers OU.
Locate and click the Terminal Services server or servers, click Action, and then click Move.
In the Move dialog box, click the new Terminal Services server or servers, and then click OK.
Click the new Terminal Services OU to verify that the move has successfully taken place.

To create a Terminal Services Group Policy object, follow these steps:
Click the new Terminal Services OU.
On the Action menu, click Properties.
Click the Group Policy tab.
Click New to create the New Group Policy object.
Click Edit to modify the group policy.

When modifications are completed, close the Group Policy editor, and then click Close to close OU Properties.

I have also ticked the NO over ride option for the policy with no luck.

However, The group policy that I have created are not taking effect.

Does Windows 2000 DC group policy work on Windows server 2003? and How can I get this working?

Thanks

James
0
Comment
Question by:intouchsystems
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 15

Accepted Solution

by:
harleyjd earned 125 total points
ID: 12070198
What options are you using from the Group Policy?

I suspect you're locking down the UI - All User Configuration stuff. As the users are not in the OU with the terminal server you need to enable loopback processing on the GP to have it apply to users in a different container.

How to Apply Group Policy Objects to Terminal Services Servers - http://support.microsoft.com/default.aspx?scid=kb;en-us;260370&sd=tech
Loopback Processing of Group Policy - http://support.microsoft.com/default.aspx?scid=kb;EN-US;231287
Locking Down Windows Server 2003 Terminal Server Sessions - http://www.microsoft.com/downloads/details.aspx?FamilyID=7f272fff-9a6e-40c7-b64e-7920e6ae6a0d&DisplayLang=en

The other thing to consider is refresh interval - by default on non-dc servers and all workstations the refresh is 90 minutes +/- 30 minutes, so potentially it could take 2 hours before your policy is applied. On the 2k server policy is refreshed by typing "secedit /refreshpolicy machine_policy /enforce" and "secedit /refreshpolicy user_policy /enforce" at a command prompt. To refresh on the w2k3 server type "gpupdate /force"
0
 

Author Comment

by:intouchsystems
ID: 12074388
Thanks

the loopback process worked.

Cheers
0
 
LVL 15

Expert Comment

by:harleyjd
ID: 12074514
So only a "b"? :)

0

Featured Post

Edgartown IT Case Study

Learn about Edgartown's quest to ensure the safety and security of the entire town's employee and citizen data. Read the case study!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Changing a few Outlook Options can help keep you organized!
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question