You can basically create an OU in AD and drag the Terminal Server into that OU. Enable group policy loopback, make sure this doesn't apply to domain admins (or whatever other groups you want with full permissions). Create a group policy for the OU you dragged the TS into. This will apply to any user that logs into this TS (minus the group you gave full access to). You can restrict everything from My Computer to the run command.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.