smoker49
asked on
Loopback GPO for Citrix is not working
Hello,
I am trying to apply my first "loopback" policy on my Citrix server. The policy I want to implement is to hide the Citrx server's local drives (C&D)
I have read several articles on how to do this, and followed them step-by-step but can not get it to work. Here is what I have done:
1. I created a new OU and moved a Citrix server in there. (I have other Citrix servers but for now I only want the local drives on this one hidden.)
2. In this OU, I created a GPO called "Loopback." User configuration has been disabled and "User group policy loopback processing mode" has been enabled and set to "merge."
3. Next, I created another GPO called "Hide Local Drives" and it is linked to the same OU the Citrix server is in.
4. Computer configuration settings have been disabled for this GPO and the setting to hide drives A though D has been selected.
5. In the security tab of the “Hide Local Drives” GPO I unchecked “Read” and “Apply Group Policy” for Authenticated Users I added two test user accounts and checked the “Read” and “Apply Group Policy.” (Note, these test user accounts are in another OU and used just for testing.)
6. On the Citrix server, I ran “gpupdate /force” and even restarted the server and still cannot get the loopback policy to work. If I link the GPO directly to the OU where my test user accounts, the GPO works but then it hides even the local drives to workstations (defeating the purpose of the loopback.)
Any suggestions as to what I may be missing?
A little bit about what I'm working with:
Citrix XenApp 6.0 running on Windows Server 2008 64-bit
I am trying to apply my first "loopback" policy on my Citrix server. The policy I want to implement is to hide the Citrx server's local drives (C&D)
I have read several articles on how to do this, and followed them step-by-step but can not get it to work. Here is what I have done:
1. I created a new OU and moved a Citrix server in there. (I have other Citrix servers but for now I only want the local drives on this one hidden.)
2. In this OU, I created a GPO called "Loopback." User configuration has been disabled and "User group policy loopback processing mode" has been enabled and set to "merge."
3. Next, I created another GPO called "Hide Local Drives" and it is linked to the same OU the Citrix server is in.
4. Computer configuration settings have been disabled for this GPO and the setting to hide drives A though D has been selected.
5. In the security tab of the “Hide Local Drives” GPO I unchecked “Read” and “Apply Group Policy” for Authenticated Users I added two test user accounts and checked the “Read” and “Apply Group Policy.” (Note, these test user accounts are in another OU and used just for testing.)
6. On the Citrix server, I ran “gpupdate /force” and even restarted the server and still cannot get the loopback policy to work. If I link the GPO directly to the OU where my test user accounts, the GPO works but then it hides even the local drives to workstations (defeating the purpose of the loopback.)
Any suggestions as to what I may be missing?
A little bit about what I'm working with:
Citrix XenApp 6.0 running on Windows Server 2008 64-bit
can you create test user in same OU and check again.
your config looks good for me.
use gpresult.msc or the group policy result wizzard to check if the gpo and the settings would be applied to the user.
try to disable the user or machine part of the gpo's later, some times there are a mistake.
use gpresult.msc or the group policy result wizzard to check if the gpo and the settings would be applied to the user.
try to disable the user or machine part of the gpo's later, some times there are a mistake.
ASKER
In response to amitkulshrestha, if I move my test user ID into the OU where my Citrix server is, yes, the policy is applied.
Just read this KB
http://support.microsoft.com/kb/231287
http://support.microsoft.com/kb/231287
ASKER
I ran the the Group Policy Results wizard set to my Citrix server and my test user ID.
The Loopback policy gets applied and looks ok.
The "hide local drive" policy is what is not working. The report under "user configuration summary lists it under the section of "Denied GPO's showing the Unique ID instead of the name of the GPO and says it's "Inaccessible."
I checked once again, and made sure my test user ID has read and apply group policy security settings.
Any idea why the GPO is "inaccessible?"
The Loopback policy gets applied and looks ok.
The "hide local drive" policy is what is not working. The report under "user configuration summary lists it under the section of "Denied GPO's showing the Unique ID instead of the name of the GPO and says it's "Inaccessible."
I checked once again, and made sure my test user ID has read and apply group policy security settings.
Any idea why the GPO is "inaccessible?"
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Great you found the issue.
ASKER
The configuration of the loopback policy may differ from what other users do.