Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Terminal Services and Loopback processing

Posted on 2006-07-20
3
489 Views
Last Modified: 2008-02-26
I am attempting to build a Terminal Server to allow access to an accounting application to a few select users. Domain Is 2003 native and Terminal is 2003. I also want to enable the TS Lockdown GPO settings. I have created a seperate OU (container) for the terminal server and placed the server within. I enabled the loopback processing via a GPO on this container along with the TS Lockfdown GPO settings. Originally, I had created a group named TS Users and added the select few user accounts to this group- and placed this group within the container. This did not work,and in a previous question- I learned that you cannot apply GPO's to groups. Then I moved the select users accounts to the Terminal Server OU (container) and it DID work. They logged in, the application popped up, and all TS Lockdwon settings were applied.

BUT- when the users logged into their WORKSTATIONS, the TS Lockdown GPO settings applied to their accounts on their workstations as well. I did enable loopback processing for the GPO assigned to this container. What am I doing wrong? I want this GPO to ONLY apply when they are in a terminal session. When they are not in a term session, I want the standard GPO's link to the domain (ie. default domain policy, etc...) to apply. Please help...

If I delegate this to all authenticated users (read and apply GPO), will this apply to everyone on their individual workstations- or did this previously happen b/c I had placed the TS Users account in the container???
0
Comment
Question by:Trihimbulus
  • 2
3 Comments
 
LVL 84

Expert Comment

by:oBdA
ID: 17147224
Do NOT, I repeat, do NOT place the user account in or below the OU with the TS account where you applied the loopback policy. Put them back into a "normal" OU.
Once you apply a loopback policy to a computer, and then add user policies to this OU, the user policies will apply to ALL users logging on to that machine, regardless of which OU their accounts are in.
Use one GPO to enable the loopback setting only; leave the default permissions for this GPO, and disable the User Configuration (it's not needed, and disabling it will speed up the process a bit).
Create another GPO in which you configure the locked down settings for the users. To prevent locking out administrators, use the group you already created: remove the default "Authenticated Users" from the Read and Apply permissions of the TS user GPO, and set these permissions for the security group instead.
0
 

Author Comment

by:Trihimbulus
ID: 17147393
Thanks! Do I have to keep the "TS Users" security group in the container- or can it just be in the default Users container?

Do I need to set "Replace" for Loopback processing or "Merge"?

What part of the User Configuration in the Loopback GPO to I need to disable to speed things up?
0
 
LVL 84

Accepted Solution

by:
oBdA earned 500 total points
ID: 17147525
1. It doesn't matter at all in which OU the security group is stored.
2. The loopback mode to choose depends entirely on what suits you better.
3. This is not a policy; in the properties of the GPO, you can disable the user configuration or the computer configuration (or both). Since the user configuration isn't needed in the Loopback GPO, you can set this to disabled. In the same way, if you don't use Computer Configuration settings in the lockdown GPO, you could disable the Computer Configuration part in this one.

Loopback Processing of Group Policy
http://support.microsoft.com/?kbid=231287
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The HP utility "HP Lights-Out Online Configuration Utility for Windows Server 2003/2008" could be of great use when it comes to remotely configure a HP servers ILO WITHOUT rebooting the server. We would only need to create and run scripts using thi…
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question