Terminal Server Group Policy

I have an enviroment where we are running a couple of Terminal Servers as well as a bunch of PC's.  I want to create a locked down Group Policy object that will only apply to user when they are logged onto the Terminal Server.  I have an OU with only my Terminal Servers in it, and I have s Separate OU with all of my users.  I have two issues right now. Currently the policy is applying on the User's PC which we cannot have.  The only other thing that I can think of doign is enable Loop Back Policy, but I don't the administrative users to have any policy applied.  What other options do I have here.
LVL 9
rshooper76Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

b0fhCommented:
The answer is to use multiple policies; Use a policy on the Users' OU (to be applied anywhere the users in the OU  login) and a separate policy for the TS machines (for anyone logging into a Terminal Server in that OU).  

Did you run a gpupdate after applying the policies?  Did you reboot the Terminal Server(s)?  The policy must be "read" to be used.  It sounds as if your user policy has been read already, but might have been applied improperly.

It sounds as if you're halfway there, but may have just mixed up your policies.
0
oBdACommented:
There is no other option than using the Loopback processing.
To prevent the loopback policies from applying to admin accounts, you can use security group filtering. Create one GPO enabling the Loopback processing, leave the default security settings. Create a different GPO for the user settings, create a security group, remove the default "Authenticated Users" from the Read and Apply permissions to this GPO (or from the Security Filtering list if using GPMC), and add this security group instead. Add all user accounts to which the policies should be applied to the group.

Loopback processing of Group Policy
http://support.microsoft.com/?kbid=231287
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Microsoft Server OS

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.