Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Windows 2000 group policy

Status
Not open for further replies.

Hof

MIS
Mar 27, 2002
99
SE
Hi
I'm not sure if I should ask this question in this forum or in the W2k server forum but I'll try here first.
Environment is as follows:
Windows 2000 AD domain
Windows 2000 TS/Citrix servers
Windows 2000 Professional clients

What i want to do is to apply the user part of W2k Group Policies to the users only when they log on to the Citrix-server and not when they log on to their desktop computers. How should I organize the users in OUs and apply the group policies to achieve this the simplest way?

All ideas are greatly appreciated.
 

Well, this quesion is more suitable in Win2K Forum, but I think if you know Citrix, you know NT or 2000 well. Anyway!

1. You would create an OU.
2. Place all the Citrix Servers under this OU
3. Apply the policy to the OU.

I'm assuming you know how to do the above without details. If not...reply back.

Hope that helped. Dave Namou, MCSE CCEA
 
Thanks for your answer
Sure that is simple enough and I have thought of this solution but in this way only the computer part of the group policy is applied since you dont have any user accounts in the OU. I want to apply the user part also but as I said only when the user logs on to the Citrix servers. Any more ideas?

/Hof
 
You can configure the permsissions on the GPO so that users in certain groups would get certain permissions.

For example...
Lets say you create a GPO (Group Policy Object) on the OU which your Terminal Servers are in. We'll call it GPO-WTS. And you have 3 groups that will use these servers. You can create 3 different group policies and applie them all to GPO-WTS. When a user logs on, he will get the policy configured for the group he's in.

One final note.... you must remove the "Authenticated Users" group from GPO-WTS or uncheck the "Apply" settings. Because "Authenticated Users" is basically the EVERYONE group which includes the Adminstrators.

Hope that helps Dave Namou, MCSE CCEA
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top