?
Solved

Using group policy to restrict access of software for some users on terminal services?

Posted on 2011-09-25
2
Medium Priority
?
300 Views
Last Modified: 2012-05-12
hi guys,

If I wanted some people to have microsoft office applications available to them when they log onto terminal services and others to not have access, then how would I implement this with group policies?

Many thanks
Yashy
0
Comment
Question by:Yashy
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 57

Accepted Solution

by:
Pete Long earned 1000 total points
ID: 36595658
Setup some manditory profiles (make sure they are set as the "Terminal Services Profile" on the user object in AD users and computers.)

Then you can have a non office profile and an office profile :)

Not done with GPO's though =/
0
 
LVL 39

Assisted Solution

by:Krzysztof Pytko
Krzysztof Pytko earned 1000 total points
ID: 36595662
You can create GPO with Software Restrictions and the use GPO Filtering to target only that group which shouldn't have to use software on your TS

ABout Software Restriction
http://support.microsoft.com/kb/324036

About GPO Filtering
http://technet.microsoft.com/en-us/library/cc779291%28WS.10%29.aspx
http://www.windowsnetworking.com/articles_tutorials/group-policy-security-filtering.html

but I would suggest to change NTFS settings on folders with that programs to only specified groups. Others won't be able to run software.

Regards,
Krzysztof
0

Featured Post

Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question