User Policy

  • Thread starter Thread starter andy.dyble
  • Start date Start date
A

andy.dyble

Hi

I have not created a user or group policy before now so here's my problem.

I created a user on our 2k server domain called "terminaluser", the idea
being that I could allow rrmote users to dem our software apps.
I wanted to give the user very little access, i.e can't shut down, get into
control panel, my computer etc.
I created a new policy called terminalusers.pol and saved it in a folder
called c:\tspolicies
I restricted just about anything for this user, then within User manager for
domains put this path in as the terminal server policy path.
However, when I log in via ts as this user I get the full server screen as
if I was Administrator.

My first mistake must be where to save the policy, but I also don;t know
whether I need a poilcy for each user or group. As I undserstand it
if I have a group called "sales" I can create a policy for this group and
allocate it to the "sales" group. Any advice would be welcome.

Thanks

Andy
 
If you have an AD domain, you should use Group Policies instead
(it sounds as if you used system policy editor).
To apply policies only to the TS, use "loopback processing". Check
these articles for more info:

278295 - How to Lock Down a Windows 2000 Terminal Services Session
http://support.microsoft.com/?kbid=278295

260370 - How to Apply Group Policy Objects to Terminal Services
Servers
http://support.microsoft.com/?kbid=260370

231287 - Loopback Processing of Group Policy
http://support.microsoft.com/?kbid=231287

--
Vera Noest
MCSE, CCEA, Microsoft MVP - Terminal Server
http://hem.fyristorg.com/vera/IT
--- please respond in newsgroup ---

(e-mail address removed) wrote in
 
creating an additional domain is a mistake! Redo it and add it to the
existing domain. If you are not savvy with GPOs then consider a 3rd party
tool like Applauncher. If you never messed with GPOs before, this will take
a few days to learn and properly setup vs 5 minutes of installation.
 
Hi

I tried Applauncher and it works OK, but I want to have different users with
different programs.

Andy
 
Back
Top