Solved

Windows 2008 TS Group Policy Local Policy  default user configuration

Posted on 2011-02-11
5
637 Views
Last Modified: 2012-08-13
Here is the scenario:  I have a 2008 R2 Terminal Server.  I create all the GPO's I want so as to lock things down/control access/configure the desktop. I then create a new user but the new user seems to be configured differently than what I thought I had specified in the GPO. A simple example is that the  new user gets Outlook Express on their desktop and I subsequently have to get rid of it. They may be able to run Powershell. It seems that these items come from the local policy of the TS server itself. What do I have to do to make it so that the users I create are based on a default user that is exactly the way I want it to be so that all users I create have just the desktop/rights I want them to have?

Is this what Group Preferences can remedy?

Again I have a 'perfect' new user in mind and I want all new users to get that exact same template.
0
Comment
Question by:lineonecorp
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 34876470
0
 

Author Comment

by:lineonecorp
ID: 34877197
Thanks for the reads but I've seen these articles before. Unless I didn't read deep enough they do not address the issue I have - basically it seems some items that show up when you create a user come from the local policy of the Terminal Server itself as opposed to what I might have specified in Group Policy. Again a good example is that when I create a user they get Outlook Express on their desktop - how do I stop this from happening. Nothing in the GPO that I can see seems to be able to stop this from happening.
0
 

Author Comment

by:lineonecorp
ID: 34877313
I dug through and found this article which is relevant.

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/2003_Server/Q_21691790.html


The solution in here that I liked was:

del "%userprofile%\start menu\programs\outlook express.lnk"

Is there any instead of doing this in the login script I could to it via a Group Policy or Group Preference?  
0
 
LVL 47

Accepted Solution

by:
Donald Stewart earned 500 total points
ID: 34879079
0
 

Author Comment

by:lineonecorp
ID: 34880000
Great.  I got the idea  now. Thanks.
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article outlines the process to identify and resolve account lockout in an Active Directory environment.
Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question