How to Lock Desktop and Menu Settings for TS Users

  • Thread starter Thread starter Valerie
  • Start date Start date
V

Valerie

I have a WIN2003 server - I have created Terminal Service
Roaming profiles - copied each user their own userid
folder under the shared roaming profile directory.
Some users log on - the have some of the restrictions I
imposed - like removing all the links in the start menu -
some log in and get all the links from the default user.
And even if I delete the links out of the profiles
including their roaming profile - some come back.
This is not consistent - I created everyone and everything
exactly the same & bam - nothing stays as it should.

*This is what I need to do:
I need to have a user log on to a specific Terminal
Service server - their desktop should only have Remote
Desktop icon and PcAnyWhere icon. No recycle bin.
Nothing on the Start Menu except LogOff. They should not
be able to right click the Start button. Nothing - make
no changes -
Anyone - please let me know how to accomplish or send me a
link to a paper that explains it. Anything I do hopefully
can be easily recreated so our Data Security area can
create IDs - add them to a group and create their TS
Roaming profile without a lot of work.
Thankx for any help!
Valerie
 
Do you have a domain (NT4) or Windows 2000 Active Directory?
If using AD what you need is to create a GROUP POLICY.
If it is NT4 domains, a policy using POLEDIT and template files (.ADM) that
you can get at thethin.net.

--
Cláudio Rodrigues, MVP
Windows 2000/NT Server
Terminal Services

http://www.terminal-services.NET

-> The only Terminal Services Client for DOS.
-> The only customized RDP5.1 client with the close button disabled! :-)
-> Developers of SecureRDP, the BEST security utility for TS!

Do NOT email me directly UNLESS YOU KNOW ME or you are a Microsoft
MVP/Employee.
Use my support page on my website to submit your questions directly.
 
I have a Windows 2003 Active Domain - but it is only at
2000 level.
I have created an OU for the server & a GPO for the
server - the GPO is set with Computer settings & pieces of
it works - but not all and what works on some doesn't work
on others. The users are new user ids - never used - they
are in the same OU (not the server one) - they belong to
the same group which is only for them to be a part of the
remote desktop group on the server & the results are
different! It make no sense.

I wish there was a way that I could make it that when
these users access this terminal server they get this
desktop with no access to anything other than these apps.
But MS makes it so that when a user logs on - it creates
the local profile under Doc and Settings & self generates
other links on the menu - if I could stop the self
generating piece I would be home free ! possible registry
change?
 
Back
Top