Terminal Services and Loopback processing
Posted on 2006-07-20
I am attempting to build a Terminal Server to allow access to an accounting application to a few select users. Domain Is 2003 native and Terminal is 2003. I also want to enable the TS Lockdown GPO settings. I have created a seperate OU (container) for the terminal server and placed the server within. I enabled the loopback processing via a GPO on this container along with the TS Lockfdown GPO settings. Originally, I had created a group named TS Users and added the select few user accounts to this group- and placed this group within the container. This did not work,and in a previous question- I learned that you cannot apply GPO's to groups. Then I moved the select users accounts to the Terminal Server OU (container) and it DID work. They logged in, the application popped up, and all TS Lockdwon settings were applied.
BUT- when the users logged into their WORKSTATIONS, the TS Lockdown GPO settings applied to their accounts on their workstations as well. I did enable loopback processing for the GPO assigned to this container. What am I doing wrong? I want this GPO to ONLY apply when they are in a terminal session. When they are not in a term session, I want the standard GPO's link to the domain (ie. default domain policy, etc...) to apply. Please help...
If I delegate this to all authenticated users (read and apply GPO), will this apply to everyone on their individual workstations- or did this previously happen b/c I had placed the TS Users account in the container???