Solved

Terminal Server - Best Pratice

Posted on 2013-05-30
7
365 Views
Last Modified: 2013-06-01
Hi Experts,

I hope you can help me. I'm after opinion really from real case examples. We recently have started to provide terminal services for some of our clients. These clients primarily use office, and a few other programs, and connect to our system via citrix

We have applied much of the security restrictions from Microsoft best practice documentation for terminal servers 2003, but in some ways this is a bit too restrictive

Some of problems users are facing are the following;

Unable to click on links in a spread sheet that map to files stored else where
Every time they double click on a folder or drive it opens in a new window

Also the in-ablity to right click has been problematic so we have had to enable that


My questions for you are the following

Any ideas on how to resolve these issues
How restrictive in your experiences do you make your terminal servers?
And any other advice?
0
Comment
Question by:FSIFM
  • 3
  • 3
7 Comments
 
LVL 2

Expert Comment

by:Chris_Ryan81
ID: 39207468
I have worked for a few hosted services companies, all of which use Citrix, policies varied, client to client, and sometimes there would be a power user and regular user category.  I restrict as much as I can without being overly invasive.  For example, if opening a link from an excel spreadsheet is needed for users to complete their job, it is what it is.  

Some clients (Large banks, CC companies) would provide minimum hardening, so anything that went against those agreements we really easy to deal with "Have you CSIO sign this and I will disable it"... That almost never happened.

As for advise, if only 5 users need the ability to click links or use right click, create a GPO using security filtering so that only they can open a link.
0
 
LVL 4

Author Comment

by:FSIFM
ID: 39207480
Cheers Chris,

Any idea what policies are cause the adverse behavior I've mentioned? I have look through them but nothing stands out presently, especially not why multiple windows are opening
0
 
LVL 2

Accepted Solution

by:
Chris_Ryan81 earned 500 total points
ID: 39207489
Looks like it may get caused if you turn on "Classic View" through a GPO.  Check these links out -

http://www.petri.co.il/forums/showthread.php?t=2137
and
http://www.edugeek.net/forums/windows-7/62478-set-open-each-folder-same-window-double-click-open-item.html

It looks like that reg key holds a lot of values, so I would probably create a local user and setup the folder options how you would like the end user to see, and grab the reg key from your setup account and apply it to your users with a Policy Preference or log on script.
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 4

Author Comment

by:FSIFM
ID: 39207653
Awesome! Chris that totally fixed our issues

The only problem i now have is only new users are fixed. Just like link number 2, existing users retain the problem unless their profiles are removed

Any idea on how to resolve it without removing their profiles?
0
 
LVL 2

Expert Comment

by:Chris_Ryan81
ID: 39208411
Did you use a logon script or GPP?
0
 
LVL 8

Expert Comment

by:barrykfl
ID: 39209823
I just removed the required registy and make the IE browser the fix link and without any rdirectly .

Your make harden to control the users by GPO no access of other folder , or only allow that xls .
0
 
LVL 4

Author Comment

by:FSIFM
ID: 39213207
I ended up removing their profiles out of hours and re-creating them. Thank you all for your assistance
0

Featured Post

DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Citrix policies are the most efficient method to configure and tune XenDesktop environments, allowing organizations to control connection, security and bandwidth settings based on various combinations of users, devices or connection types.  Citrix …
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question