Re: best method to restrict application execution on terminal servers



If you apply the user configuration to the terminal servers through Loopback
mode then it will also apply to the domain admins group even with a deny
permission for the DAs as the terminal servers will be applying the
policy -not the users.

Better do as you say but apply it to the users (so don't use loopback). The
scope of the GPO will depend on the logical location of the users and the
number of non-TS users, etc.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net



.



Relevant Pages

  • Re: Loopback processing
    ... I'm in the process of setting up loopback processing and would like ... All my settings are in the computer configuration and i have disabled ... assuming that I apply it to the same OU that the Terminal servers are ...
    (microsoft.public.windows.terminal_services)
  • Re: best method to restrict application execution on terminal servers
    ... through terminal servers on not at there regular desk PC? ... > policy -not the users. ... > Better do as you say but apply it to the users (so don't use loopback). ...
    (microsoft.public.windows.server.active_directory)
  • terminal server security
    ... I am trying to secure two w2k terminal servers. ... I want to enable right click on the task bar but deny ...
    (microsoft.public.win2000.security)