Re: Terminal Server GPO Issue



can u post the output of "gpresult /v" while reproducing the issue? I
would also like to see the name of the GPO in question, the DN of the
containing OU of the server that is NOT supposed to get the GP, etc.


Jon - Server Admin wrote:
we are already using loopback policy processing on these GPO's. and no, the
user accounts are not in the same OU as the servers mentioned.

"strongline" wrote:

Are affected users in the same OU that contains those 6 TS?
Keep in mind that User Configurations will be applied to user accounts
only, while Computer Configurations will be applied to only computer
objects.

All your desired settings are User-specific settings - meaning they
were applied through uers objects only. It should not take effect if
you linked it to an OU that contains only TS servers.

If you want to apply user-specific settings onto certain computers, you
will have to enable lookback. Just google "group policy loopback", you
will get more than enough info.

Jon - Server Admin wrote:
I have a GPO that contains user and computer settings for a group of users
being applied to 6 Terminal servers running 2003 that are in a certain OU
within our Active Directory. Within this policy are folder redirection
settings for appdata, my docs, desktop, and start menu. Their is also a
logon script that is set to run in the policy as well as many other settings.

The problem is that when a user logs onto a different terminal server that
is not in this OU, they get their folders redirected and the logon script is
running as well. So it appears that these GPO settings are being applied
when they should not be. I do not know why?

Also, if I am logged onto one of these other servers that shouldn't apply
the policy, I am running RSOP.msc and it doesn't show any of the settings
from my GPO being applied?

I am baffled.

Any ideas why this might be happening?



.



Relevant Pages

  • Re: GPO Update Problem (SYSVOL access via UNC)
    ... Server Security and Auditing Policy ... This list only includes links in the domain of the GPO. ... The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.win2000.group_policy)
  • Re: GPO Update Problem (SYSVOL access via UNC)
    ... > Server Security and Auditing Policy ... > This list only includes links in the domain of the GPO. ... > The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.win2000.group_policy)
  • Re: SCW question.
    ... Created a new Server and installed IIS. ... and saw that the default rights for IUSR and IWAM users are there. ... Server to the domain without and GPO's applied...Local Security policy ... rights (which coincides with my Member server GPO settings). ...
    (microsoft.public.windows.server.security)
  • Re: GPO not picking up computer settings
    ... to the domain container with the password/account settings you want. ... for password/account settings and from what GPO. ... buying any of the highly rated AD or Group Policy books you see at Amazon or ... I have changed all the passwords back to what they were so users are now ...
    (microsoft.public.windows.server.security)
  • Re: Group Policy is now inhibiting the Administrator account
    ... under Group Policy Objects - those are the individual GPOs. ... You can apply any given GPO to one or more OUs, ... I use all of the default security in SBS, ... log on to the server with your own account. ...
    (microsoft.public.windows.server.sbs)

Loading