Re: GPO problems when logon to kerberos-realm

From: Michael Sundström (anonymous_at_discussions.microsoft.com)
Date: 09/20/04


Date: Mon, 20 Sep 2004 00:53:46 -0700

Hej Tim,

I understand your reasoning but the strange think is that
when I put the same policy on an OU with e.g. a Windows
2000 or a Windows XP client there is no problem applaying
the policy settings to the client when logon to the
kerberos-realm (non-Microsoft). It seems only to be a
problem when logon to a Terminal Server.

Does anyone have an explantion for this behavior?

Regards,
/Michael Sundström
Royal Institute of Technology, Sweden

>-----Ursprungligt meddelande-----
>Hi Michael-
>
>If I understand correctly you have used KSETUP.EXE to map
users your domain
>users (ALLUSERS). That sounds like it would work,
however the other realm
>(the non-Microsoft one) will not have the information
that the group policy
>processing will need to identify the user principal and
verify that they
>have the required permissions and access to that policy
or policies (the AD
>portion of it and the file system portion located in the
SYSVOL).
>
>This access is identified by using security identifiers
(SID) attributes on
>the Active Directory account for the user principal. I
don't know how a
>non-Microsoft realm would be able to pass that along to
your terminal server
>when creating the user environment at logon. If I recall
correctly, most
>other environments do not have a security identfier (SID)
to pass along at
>logon. That being the case, the loopback processing mode
would not be an
>option when your users logon using their credentials from
the other Kerberos
>realm (the non-Microsoft one).
>
>If anyone in the newsgroup has some good interopability
experience to pass
>along for Michael please add to this thread.
>--
>Tim Springston
>Microsoft Corporation
>This posting is provided "AS IS" with no warranties, and
confers no rights.
>
>
>"Michael Sundström" <misun@nada.kth.se> wrote in message
>news:3Mm2d.103479$dP1.372838@newsc.telia.net...
>> Hej from Sweden,
>>
>> We have a Terminal Server running on Windows Server
2003. We locked it
>> down
>> according to Microsoft white paper how to lock down a
Terminal Server.
>>
>> We configured a kerberos realm with "ksetup" and using
kerberos as
>> authentication method for our users.
>>
>> Because our user are not placed in the same OU as the
Terminal Server we
>> have enabled "User Group Policy loopback processing
mode" and it works
>> perfectly as long as the users logon to the normal
windows domain. But
>> when
>> the users logon to the kerberos-realm the GPO settings
will not be
>> applied.
>> It seems that the loopback processing mode does not
work when logon to the
>> kerberos-realm.
>>
>> Does anybody know why there should be such a problem
when using GPO and
>> logon to a kerberos-realm?
>> Could it be possible that we have to "activate" that
the GPO settings also
>> should work for the kerberos-realm?
>>
>> Thanks in advance!
>>
>> /Michael
>>
>
>
>.
>



Relevant Pages

  • Re: Server 2K3 Remote Desktop Access - is this right place?
    ... All roads for that particular error of 'You do not have access to logon to ... On Windows Server 2003, launch GPEDIT.MSC from Start -> Run. ... Drill down and expand the following for Local Computer Policy: ... > Strange - when I activate the Remote Desktop Terminal from the server, ...
    (microsoft.public.win2000.advanced_server)
  • Re: Terminal Server and Local Policy
    ... It is not a question of "user profiles" (you can have those on Windows 98 ... A Terminal Server can not "override" client ... icon to connect to the Terminal Server, they can not logon to the Terminal ... "Remote Desktop Users" group have the right to logon via Terminal Services. ...
    (microsoft.public.windows.server.general)
  • Re: local GPO question
    ... You just had the option of> synchronous or asynchronous policy processing. ... Windows XP lets you wait for the network or not. ... I had understood that turning off Fast logon optimization in>> XP ...
    (microsoft.public.win2000.group_policy)
  • Re: local GPO question
    ... synchronous or asynchronous policy processing. ... Windows XP lets you wait for the network or not. ... > "Note that Windows XP clients support Fast Logon Optimization in any ...
    (microsoft.public.win2000.group_policy)
  • RE: Controlling access to drive C and IE settings
    ... I suggest you refer to the following article to use the policy below to ... restrict local drives. ... Locking Down Windows Server 2003 Terminal Server Sessions ...
    (microsoft.public.win2000.group_policy)

Loading