Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Blocking GP inheritance for admin account on MS TS

Status
Not open for further replies.

headrush

Technical User
Jul 10, 2002
31
0
0
US
I am building a WIN2k server running Terminal Services. I would like to lock down the desktop, control panel, etc, to make it more secure from the users connecting but if I use a computer policy, the admin account's desktop will be locked down as well. I created a OU, created the policy on the OU and placed the Terminal Server in it but how can I block the policy inheritance for the admin account when we log in.
 
Apply the policy at domain level, and then modify the filters....filter this on SecurityGroups, and remove the Everyone or Authenticated Users entry. Add all groups that you want this policy to apply to.

Hope this Helps.

Neil J Cotton
njc Information Systems
Systems Consultant
 
Is there a way to do it without modifying the default domain policy?
 
Yes, you would be creating a new policy at that level. Don't touch the default policy.
 
NEVE REDIT DEFAULT DOMAIN POLICY

The only time you should EVER touch the Default Domain Policy is to configure the password policy.

All other settings should be done in a new GPO, I just said link it at domain level.

Hope this Helps.

Neil J Cotton
njc Information Systems
Systems Consultant
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top