Solved

Loopback GPO for Citrix is not working

Posted on 2012-12-27
8
999 Views
Last Modified: 2013-01-01
Hello,

I am trying to apply my first "loopback" policy on my Citrix server. The policy I want to implement is to hide the Citrx server's local drives (C&D)

I have read several articles on how to do this, and followed them step-by-step but can not get it to work. Here is what I have done:

1. I created a new OU and moved a Citrix server in there. (I have other Citrix servers but for now I only want the local drives on this one hidden.)

2. In this OU, I created a GPO called "Loopback." User configuration has been disabled and "User group policy loopback processing mode" has been enabled and set to "merge."

3. Next, I created another GPO called "Hide Local Drives" and it is linked to the same OU the Citrix server is in.

4. Computer configuration settings have been disabled for this GPO and the setting to hide drives A though D has been selected.

5. In the security tab of the “Hide Local Drives” GPO I unchecked “Read” and “Apply Group Policy” for Authenticated Users I added two test user accounts and checked  the “Read” and “Apply Group Policy.” (Note, these test user accounts are in another OU and used just for testing.)

6. On the Citrix server, I ran  “gpupdate /force” and even restarted the server and still cannot get the loopback policy to work. If I link the GPO directly to the OU where my test user accounts, the GPO works but then it hides even the local drives to workstations (defeating the purpose of the loopback.)

Any suggestions as to what I may be missing?

A little bit about what I'm working with:
Citrix XenApp 6.0 running on Windows Server 2008 64-bit
0
Comment
Question by:smoker49
  • 4
  • 3
8 Comments
 
LVL 42

Expert Comment

by:Amit
ID: 38723686
can you create test user in same OU and check again.
0
 
LVL 23

Expert Comment

by:Dirk Kotte
ID: 38723803
your config looks good for me.

use gpresult.msc or the group policy result wizzard to check if the gpo and the settings would be applied to the user.
try to disable the user or machine part of the gpo's later, some times there are a mistake.
0
 

Author Comment

by:smoker49
ID: 38724023
In response to amitkulshrestha, if I move my test user ID into the OU where my Citrix server is, yes, the policy is applied.
0
 
LVL 42

Expert Comment

by:Amit
ID: 38724054
0
Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:smoker49
ID: 38724304
I ran the the Group Policy Results wizard set to my Citrix server and my test user ID.
The Loopback policy gets applied and looks ok.

The "hide local drive" policy is what is not working. The report under "user configuration summary lists it under the section of "Denied GPO's showing the Unique ID instead of the name of the GPO and says it's "Inaccessible."
I checked once again, and made sure my test user ID has read and apply group policy security settings.

Any idea why the GPO is "inaccessible?"
0
 

Accepted Solution

by:
smoker49 earned 0 total points
ID: 38724441
I figured out what the problem was. Contrary to a set of instructions I was following to uncheck "read" and "apply group" policy for Authenticated Users for the GPO and give it to the security group instead is not working. I gave Authenticated Users the "read" permission and my loopback policy now seems to be working fine.
0
 
LVL 42

Expert Comment

by:Amit
ID: 38724450
Great you found the issue.
0
 

Author Closing Comment

by:smoker49
ID: 38734230
The configuration of the loopback policy may differ from what other users do.
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
google apps AD sync for groups 3 46
XenDesktop 7.5 and Personal Certificates 9 37
cannot create more new mailboxes EX2013 2 35
cant install rsat on win 7 13 44
One of the most frustrating experiences a help desk technician will ever encounter is when a customer comes to them with a solution of their own invention and expects the tech to implement it. This often happens when people with a little bit of tech…
You may have a outside contractor who comes in once a week or seasonal to do some work in your office but you only want to give him access to the programs and files he needs and keep privet all other documents and programs, can you do this on a loca…
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now