Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Terminal Server - Best Pratice

Posted on 2013-05-30
7
Medium Priority
?
370 Views
Last Modified: 2013-06-01
Hi Experts,

I hope you can help me. I'm after opinion really from real case examples. We recently have started to provide terminal services for some of our clients. These clients primarily use office, and a few other programs, and connect to our system via citrix

We have applied much of the security restrictions from Microsoft best practice documentation for terminal servers 2003, but in some ways this is a bit too restrictive

Some of problems users are facing are the following;

Unable to click on links in a spread sheet that map to files stored else where
Every time they double click on a folder or drive it opens in a new window

Also the in-ablity to right click has been problematic so we have had to enable that


My questions for you are the following

Any ideas on how to resolve these issues
How restrictive in your experiences do you make your terminal servers?
And any other advice?
0
Comment
Question by:FSIFM
  • 3
  • 3
7 Comments
 
LVL 2

Expert Comment

by:Chris_Ryan81
ID: 39207468
I have worked for a few hosted services companies, all of which use Citrix, policies varied, client to client, and sometimes there would be a power user and regular user category.  I restrict as much as I can without being overly invasive.  For example, if opening a link from an excel spreadsheet is needed for users to complete their job, it is what it is.  

Some clients (Large banks, CC companies) would provide minimum hardening, so anything that went against those agreements we really easy to deal with "Have you CSIO sign this and I will disable it"... That almost never happened.

As for advise, if only 5 users need the ability to click links or use right click, create a GPO using security filtering so that only they can open a link.
0
 
LVL 4

Author Comment

by:FSIFM
ID: 39207480
Cheers Chris,

Any idea what policies are cause the adverse behavior I've mentioned? I have look through them but nothing stands out presently, especially not why multiple windows are opening
0
 
LVL 2

Accepted Solution

by:
Chris_Ryan81 earned 2000 total points
ID: 39207489
Looks like it may get caused if you turn on "Classic View" through a GPO.  Check these links out -

http://www.petri.co.il/forums/showthread.php?t=2137
and
http://www.edugeek.net/forums/windows-7/62478-set-open-each-folder-same-window-double-click-open-item.html

It looks like that reg key holds a lot of values, so I would probably create a local user and setup the folder options how you would like the end user to see, and grab the reg key from your setup account and apply it to your users with a Policy Preference or log on script.
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
LVL 4

Author Comment

by:FSIFM
ID: 39207653
Awesome! Chris that totally fixed our issues

The only problem i now have is only new users are fixed. Just like link number 2, existing users retain the problem unless their profiles are removed

Any idea on how to resolve it without removing their profiles?
0
 
LVL 2

Expert Comment

by:Chris_Ryan81
ID: 39208411
Did you use a logon script or GPP?
0
 
LVL 8

Expert Comment

by:barrykfl
ID: 39209823
I just removed the required registy and make the IE browser the fix link and without any rdirectly .

Your make harden to control the users by GPO no access of other folder , or only allow that xls .
0
 
LVL 4

Author Comment

by:FSIFM
ID: 39213207
I ended up removing their profiles out of hours and re-creating them. Thank you all for your assistance
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A procedure for exporting installed hotfix details of remote computers using powershell
I’m willing to make a bet that your organization stores sensitive data in your Windows File Servers; files and folders that you really don’t want making it into the wrong hands.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

578 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question