Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Terminal Server - Best Pratice

Posted on 2013-05-30
7
Medium Priority
?
369 Views
Last Modified: 2013-06-01
Hi Experts,

I hope you can help me. I'm after opinion really from real case examples. We recently have started to provide terminal services for some of our clients. These clients primarily use office, and a few other programs, and connect to our system via citrix

We have applied much of the security restrictions from Microsoft best practice documentation for terminal servers 2003, but in some ways this is a bit too restrictive

Some of problems users are facing are the following;

Unable to click on links in a spread sheet that map to files stored else where
Every time they double click on a folder or drive it opens in a new window

Also the in-ablity to right click has been problematic so we have had to enable that


My questions for you are the following

Any ideas on how to resolve these issues
How restrictive in your experiences do you make your terminal servers?
And any other advice?
0
Comment
Question by:FSIFM
  • 3
  • 3
7 Comments
 
LVL 2

Expert Comment

by:Chris_Ryan81
ID: 39207468
I have worked for a few hosted services companies, all of which use Citrix, policies varied, client to client, and sometimes there would be a power user and regular user category.  I restrict as much as I can without being overly invasive.  For example, if opening a link from an excel spreadsheet is needed for users to complete their job, it is what it is.  

Some clients (Large banks, CC companies) would provide minimum hardening, so anything that went against those agreements we really easy to deal with "Have you CSIO sign this and I will disable it"... That almost never happened.

As for advise, if only 5 users need the ability to click links or use right click, create a GPO using security filtering so that only they can open a link.
0
 
LVL 4

Author Comment

by:FSIFM
ID: 39207480
Cheers Chris,

Any idea what policies are cause the adverse behavior I've mentioned? I have look through them but nothing stands out presently, especially not why multiple windows are opening
0
 
LVL 2

Accepted Solution

by:
Chris_Ryan81 earned 2000 total points
ID: 39207489
Looks like it may get caused if you turn on "Classic View" through a GPO.  Check these links out -

http://www.petri.co.il/forums/showthread.php?t=2137
and
http://www.edugeek.net/forums/windows-7/62478-set-open-each-folder-same-window-double-click-open-item.html

It looks like that reg key holds a lot of values, so I would probably create a local user and setup the folder options how you would like the end user to see, and grab the reg key from your setup account and apply it to your users with a Policy Preference or log on script.
0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 
LVL 4

Author Comment

by:FSIFM
ID: 39207653
Awesome! Chris that totally fixed our issues

The only problem i now have is only new users are fixed. Just like link number 2, existing users retain the problem unless their profiles are removed

Any idea on how to resolve it without removing their profiles?
0
 
LVL 2

Expert Comment

by:Chris_Ryan81
ID: 39208411
Did you use a logon script or GPP?
0
 
LVL 8

Expert Comment

by:barrykfl
ID: 39209823
I just removed the required registy and make the IE browser the fix link and without any rdirectly .

Your make harden to control the users by GPO no access of other folder , or only allow that xls .
0
 
LVL 4

Author Comment

by:FSIFM
ID: 39213207
I ended up removing their profiles out of hours and re-creating them. Thank you all for your assistance
0

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
What if you have to shut down the entire Citrix infrastructure for hardware maintenance, software upgrades or "the unknown"? I developed this plan for "the unknown" and hope that it helps you as well. This article explains how to properly shut down …
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question