Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Terminal Server Group Policy

Status
Not open for further replies.

mufka

ISP
Dec 18, 2000
587
0
0
US
I'd like to enable a group policy that only applies when a user logs into a Terminal Server. The two things I need to set is the environment (open a particular program) and to disable the screen saver. I can do these things if I apply a GP to the user OU, but I don't want it to apply when they login to their own workstation. Applying it to the terminal server's OU doesn't seem to work. I've looked at the loopback processing, but haven't gotten it to work.

Thanks for any tips.
 
You're headed down the right path. What I would do is the following.

1. Create an OU for the terminal servers (computer accounts) and black group policy inheritance for that OU.
2. Create a new group policy object that enables loopback processing in the computer settings section and do your necessary user settings and link it to that new terminal servers OU.
 
I have done what you suggest and I have played with the Security Filtering to get it to only apply to a select group of users. Doing it this way doesn't seem to work - but it seems that it should. If I leave the Security Filtering at Authenticated Users, it works, but if I change it to another group, it does not. As a workaround I was able to get it to work properly by setting the security on the policy to deny "apply group policy" to the Domain Admins group. I'd still like to know why the Security Filtering doesn't work.
 
The security filtering will not work on user accounts, because it's the computer accounts that are attempting to apply it.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top