Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Terminal Services and Loopback processing

Posted on 2006-07-20
3
Medium Priority
?
502 Views
Last Modified: 2008-02-26
I am attempting to build a Terminal Server to allow access to an accounting application to a few select users. Domain Is 2003 native and Terminal is 2003. I also want to enable the TS Lockdown GPO settings. I have created a seperate OU (container) for the terminal server and placed the server within. I enabled the loopback processing via a GPO on this container along with the TS Lockfdown GPO settings. Originally, I had created a group named TS Users and added the select few user accounts to this group- and placed this group within the container. This did not work,and in a previous question- I learned that you cannot apply GPO's to groups. Then I moved the select users accounts to the Terminal Server OU (container) and it DID work. They logged in, the application popped up, and all TS Lockdwon settings were applied.

BUT- when the users logged into their WORKSTATIONS, the TS Lockdown GPO settings applied to their accounts on their workstations as well. I did enable loopback processing for the GPO assigned to this container. What am I doing wrong? I want this GPO to ONLY apply when they are in a terminal session. When they are not in a term session, I want the standard GPO's link to the domain (ie. default domain policy, etc...) to apply. Please help...

If I delegate this to all authenticated users (read and apply GPO), will this apply to everyone on their individual workstations- or did this previously happen b/c I had placed the TS Users account in the container???
0
Comment
Question by:Trihimbulus
  • 2
3 Comments
 
LVL 85

Expert Comment

by:oBdA
ID: 17147224
Do NOT, I repeat, do NOT place the user account in or below the OU with the TS account where you applied the loopback policy. Put them back into a "normal" OU.
Once you apply a loopback policy to a computer, and then add user policies to this OU, the user policies will apply to ALL users logging on to that machine, regardless of which OU their accounts are in.
Use one GPO to enable the loopback setting only; leave the default permissions for this GPO, and disable the User Configuration (it's not needed, and disabling it will speed up the process a bit).
Create another GPO in which you configure the locked down settings for the users. To prevent locking out administrators, use the group you already created: remove the default "Authenticated Users" from the Read and Apply permissions of the TS user GPO, and set these permissions for the security group instead.
0
 

Author Comment

by:Trihimbulus
ID: 17147393
Thanks! Do I have to keep the "TS Users" security group in the container- or can it just be in the default Users container?

Do I need to set "Replace" for Loopback processing or "Merge"?

What part of the User Configuration in the Loopback GPO to I need to disable to speed things up?
0
 
LVL 85

Accepted Solution

by:
oBdA earned 2000 total points
ID: 17147525
1. It doesn't matter at all in which OU the security group is stored.
2. The loopback mode to choose depends entirely on what suits you better.
3. This is not a policy; in the properties of the GPO, you can disable the user configuration or the computer configuration (or both). Since the user configuration isn't needed in the Loopback GPO, you can set this to disabled. In the same way, if you don't use Computer Configuration settings in the lockdown GPO, you could disable the Computer Configuration part in this one.

Loopback Processing of Group Policy
http://support.microsoft.com/?kbid=231287
0

Featured Post

How to Use the Help Bell

Need to boost the visibility of your question for solutions? Use the Experts Exchange Help Bell to confirm priority levels and contact subject-matter experts for question attention.  Check out this how-to article for more information.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
This course is ideal for IT System Administrators working with VMware vSphere and its associated products in their company infrastructure. This course teaches you how to install and maintain this virtualization technology to store data, prevent vuln…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…

927 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question