Re: Using AD policies with Citrix en normal desktops

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Cary Shultz [A.D. MVP] (cwshultz_at_mvps.org)
Date: 06/17/04


Date: Thu, 17 Jun 2004 06:06:16 -0400

Richard,

In addition to what Matjaz suggested ( which is, naturally, right on the
mark ) I might suggest that you use the following link to help you lock down
the TS via Group Policy:

http://support.microsoft.com/?id=278295

This will give you a start. Consider using Replace Mode! You will want to
make sure that you redirect the user's My Documents folder to the same
location via the TS GPO as you do via the 'desktop' GPO. Also, if you
choose to redirect other items ( such as the Start Menu ) then I suggest
that you create another location for that particular item ( such as
\\servername\startmenu\%username% ). If you redirect everything to the same
location you are going to have problems! Additionally, you might consider
using a security group to filter this as I am sure that you will not want
the Administrator account ( and possibly others? ) to be affected by this
GPO when logging on to the TS.

A quick note on using security groups to filter which user account objects
are affected by a particular GPO: simply create a security group and make
all of the user account objects that you want to be affected by this TS GPO
members of the security group. Next, on the GPO itself select Properties
and then select the Security Tab. First add that security group that you
created and make sure that it has the READ and APPLY GROUP POLICY rights.
Next, remove the AUTHENTICATED USERS security group.

I might suggest, though, that you set up a lab environment and play with
this, though. That is, if you have the resources!

HTH,

Cary

"Matjaz Ladava [MVP]" <matjaz@ladava.com> wrote in message
news:uUbhQf5UEHA.3336@TK2MSFTNGP11.phx.gbl...
> Use loopback policy pocessing on the OU that has TS servers
> http://support.microsoft.com/default.aspx?scid=231287
>
> Regards
>
> Matjaz
>
> "Richard Smit" <r_smit@wanadoo.nl> wrote in message
> news:1ce3901c4538a$0a8706b0$a301280a@phx.gbl...
> > Anybody who can help me,
> >
> > We want to use AD policies to, for example redirect a
> > desktop. Is it possible to detect if a user logs on to
> > terminal server and than use policy X and if the user logs
> > on to a normal desktop use policy Y because on the normal
> > desktop we don't want to redirect the desktop?
> >
> > Is this possible?
> >
> > Thanks,
> >
> > Richard Smit
> > HES Amsterdam
> >
>
>



Relevant Pages

  • Re: Security Groups in OUs
    ... APPLY GROUP POLICY rights to the GPO. ... Let's say that you have an OU in which there are 55 user account objects. ... If one does not already exist, create a security group that includes ... if you did not want to create a group with 51 members - creating one ...
    (microsoft.public.win2000.group_policy)
  • Re: Security Groups in OUs
    ... > APPLY GROUP POLICY rights to the GPO. ... > Let's say that you have an OU in which there are 55 user account objects. ... If one does not already exist, create a security group that ...
    (microsoft.public.win2000.group_policy)
  • Re: Deploying Office to a Security Group in an OU not working as expected.
    ... You do not deploy software via GPO to security groups - no matter where they ... assign software distributions to computer account objects but you can both ... assign and publish to user account objects. ... security group contains all user account objects and all computer account ...
    (microsoft.public.win2000.active_directory)
  • Re: Internet restriction
    ... use a security group to selectively filter to which user account objects ... then give it a friendly name (such as 'No Internet Access'). ... the GPO has just been created. ... there is a security group called 'Authenticated Users' that has ...
    (microsoft.public.win2000.group_policy)
  • Re: Block GPO on IP address
    ... a vanilla suggestion that you create a Site GPO for the software deployment. ... Server and use Security Group Filtering (whereby you remove the ... Authenticated Users from the Security Tab and create a Security Group and ... Let's look at the Zuerich, ...
    (microsoft.public.win2000.group_policy)