Re: User Sessions

Tech-Archive recommends: Speed Up your PC by fixing your registry



You can use gpedit.msc (Start-->Run-->gpedit.msc) to
set the policies, then deny the Administrators group access
to the %systemroot%\system32\GroupPolicy folder using
ntfs permissions.

Be careful with this approach, because if you make
strict policies without having a way to change
the permissions on the GroupPolicy folder you will need
to connect from another machine to change them, or
logon using an account that you had previously denied
access. For example, you could keep the GroupPolicy
folder properties window open until you are done
making your changes and then set the deny permission.

Another approach to consider is detailed here:

http://support.microsoft.com/kb/293655

Still another way would be to add the policies you
want to the user's registry when they logon. You
could put something in the logon script that checks
to see if they are a member of "Restricted Users",
and if so have it add the policies to their registry.

And finally, there are many third-party programs
that help with what you are trying to do. A couple
examples:

Manage-IT: www.99point9.com
WTSProfiles: www.terminal-services.net

Thanks.

-TP

"BarbS" <BarbS@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:3EEF7AF8-3336-452F-B9E9-C9F98E2A6E42@xxxxxxxxxxxxxxxx
>I have users connecting to a stand-alone windows 2003 terminal server. Is
> there anyway to lockdown their sessions (ex. no icons on the desktop) without
> active directory. I want the administrator account to see icons on the
> desktop.
>
> Thank You.


.



Relevant Pages

  • Re: which policy resets secuirty permisions on files/directories?
    ... > computer reboots or refreshes the policies, ... has set these permissions on that folder or possibly a parent folder. ... think the problem is in the local group policy on the computer. ...
    (microsoft.public.win2000.security)
  • Re: Searching items in non-visible folder?
    ... If you logon using an existing profile, those permissions apply to code ... So if the user doesn't have read permissions for a folder, ...
    (microsoft.public.outlook.program_forms)
  • Re: Searching items in non-visible folder?
    ... All I'm testing is a simple Logon script for now: ... > If you logon using an existing profile, those permissions apply to code ... >> items in the folder looking for the messages that I want? ...
    (microsoft.public.outlook.program_forms)
  • Re: NTFS file/folder permission to a computer...
    ... So isn't there a way to permit access to a file or folder for all users ... logon from that computer? ... All accesses are checked against permissions ...
    (microsoft.public.security)
  • Re: AVG SCAN
    ... It sounds like the program has a lack of permissions to her profile folder ... or maybe she has encrypted some files with EFS file encryption if using ... >I have 4 family users on my home pc, each with our own logon. ...
    (microsoft.public.security)