Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Locking down desktops with Server 2000

Status
Not open for further replies.

tekkid

Technical User
Dec 28, 2001
50
US
Hey folks,

I am wanting to lockdown desktops using Server 2000 and group policies. I have read about this before but do not know enough about it to complete my task. I was hoping that some of you might have some helpful info and/or know of some documentation that clearly defines these steps. Here is my project info :


I have Server 2k installed with AD-

User (A) will have access to the local desktops ( email,MS office, etc. ),including Citrix to access the terminal servers.

User (B) will only have access to Citrix with one icon on the desktop that will connect them to the terminal servers where they will access mail, office, etc. and no items in programs or the start menu but log off/ shut down.


I want to set up policies for both users from the 2k Server with AD and push these policies across the network to the machines. Is this possible? where do I start?

Thank you in advance...

kidd
 
Thanks mattwray for the responce.

Actually, I'm wanting to setup policies from the Server to push out to each computer on the network. In otherwords, I want to have a policy to remove certain icons from some machines. Other machines I want to allow access to certain icons, etc.

I want to have the ability to edit what icons the user has on his or her machine and manage that from the server through group policies in AD.

Hope that makes sense.

Thanks,

Kidd
 
The first thing you have to do is create OU's for the 2 different kinds of users. Then you can look in the GPO snap-in under User Config-> Admin Templates, Start Menu and Desktop for the removal of Icons.

I don't think there will be enough options though. I think you will have to create your default profile for User (A). Then create a default profile for User (B). Store the 2 profiles on a server and point the correct user profiles to the correct directory within AD Users and Computers...



Thanks,

Matt Wray
MCSE, MCSA, MCP, CCNA

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top