RE: Can't manage Local Users and Groups on Win2K terminal server

From: Vera Noest [MVP] (vera.noest_at_remove-this.hem.utfors.se)
Date: 01/25/05


Date: Tue, 25 Jan 2005 14:10:40 -0800

Then it seems that your GPO isn't applied as you want it, because
you still see the effects of the restrictive Default Domain GPO.

I'm not exactly sure either if what you are trying to do should be
done this way. You say that your TS policy "blocks" the Default
Domain Policy, but I assume you mean that you undo the settings? Or
have you explicitly set "Block inheritance"? Have you verified if
the Default Domain policy allows to be blocked or undone? Maybe it
uses the "No Override" setting?

 --
Vera Noest
MCSE, CCEA, Microsoft MVP - Terminal Server
http://hem.fyristorg.com/vera/IT
 --- please respond in newsgroup, NOT by private email ---

"=?Utf-8?B?R3JlZ0I=?=" <GregB@discussions.microsoft.com> wrote on
25 jan 2005 in microsoft.public.windows.terminal_services:

> Ooppss - In the last line, I meant to say I have a user loopback
> GPO in place to block the local user/group restriction coming
> down from the default domain policy.
>
> Thanks,
> Greg
>
> "GregB" wrote:
>
>> We have a Win2K TS box in a full 2003 AD environment (including
>> 2003 Forest functional mode). The issue is we cannot manage
>> any local users and groups when we logon through Terminal
>> Services using an AD based user ID. When I open the Computer
>> Management MMC by right-clicking on My Computer, the Local
>> Users and Groups doesn't appear. If I logon on locally,
>> everything works as expected. The only way I can manage local
>> users/groups is by logging on with a local administrator ID.
>> In my default domain policy, I do have a restriction on
>> managing Local Users and Groups enabled. However, I have a
>> user loopback policy GPO set to replace that should block that
>> restriction.
>>
>> Any thoughts?
>>
>> Thanks,
>> Greg



Relevant Pages

  • Re: Evt ID 1085 GP client-side extension IE ZoneMapping failed to
    ... Microsoft Windows XP Operating System Group Policy Result tool v2.0 ... GPO: Default Domain Policy ... GPO: Support Staff Policy ...
    (microsoft.public.windows.server.active_directory)
  • Re: GROUP POLICY
    ... yes, same machine, i suspect the backup DC not updated with the gpo which I ... domain policy are applied, that's by design. ... Microsoft Windows XP Operating System Group Policy Result ... Computer Setting: 3 ...
    (microsoft.public.windows.server.active_directory)
  • Re: Evt ID 1085 GP client-side extension IE ZoneMapping failed to
    ... GPO: Default Domain Policy ... GPO: GHS-SMS-BUS WSUS Computer ... GPO: Support Staff Policy ...
    (microsoft.public.windows.server.active_directory)
  • Re: GROUP POLICY
    ... domain policy are applied, that's by design. ... Microsoft Windows XP Operating System Group Policy ... GPO: Default Domain Policy ... Computer Setting: 3 ...
    (microsoft.public.windows.server.active_directory)
  • Re: Aftermath of RDIRCMP.EXE?
    ... Why not just make the Default Domain Policy back to default, which wiill eliminate any possibility that anything you change in there will affect the domain adversely. ... Then create the OU, and as Jorge suggested, link the GPO you previously created, or if you haven't created one, create one with the necessary settings. ... Also, just an FYI, there was another thread recently posted with a similar question, including an OU/GPO design question. ...
    (microsoft.public.windows.server.active_directory)