Re: Group Policy Problem Terminal-Server

Tech-Archive recommends: Speed Up your PC by fixing your registry



Hallo Thorsten,
thanks for your answer (German is correct).
I know the link for www.gruppenrichtlinien.de.
We implement the grp's etc. on the same way described on this web-page.
grpresult show's us, that a user from another OU like OU_TServer use
the policy of his home-ou and not from ou_tserver. User's directly in
ou_tserver
use the policy form ou_tserver.
Because it works correctly for over a 1/2 year and nothing changed during
this time (only security patches on the dom-controllers ! NOT on the TServer)
we suggest, that one of this patches is the reason but don't know.
--
Technik - MoDa


"ThorstenK" schrieb:

> hmm...loopback processing in the Terminalserver GPO should normaly do it.
>
> As i see MoDa seems to be German ("Domaene", and "Fibu") too, so i post a
> link to a very good german Page adressing GPOs.
> just to cover the basics again:
> http://www.grurili.de/HowTo/Terminal_Server.htm
>
> Use gpresult with the Users to troubleshoot. Also run it when you moved to
> user to the TS OU.
> If you have a 2003 Server install Groupolicy editor and use the "show me
> User x with Server y" to see the effective settings.
>
> "MoDa" <MoDa@xxxxxxxxxxxxxxxxxxxxxxxxx> schrieb im Newsbeitrag
> news:D7557FF0-B706-4FB0-86D5-E45A01EFA8AB@xxxxxxxxxxxxxxxx
> > Situation: (Win3K Dom.)
> >
> > Domaene.local
> > |
> > = Dom-Controller
> > | |
> > | = Srv-Server1 (Dom-Server)
> > | = Srv-Server2 (Dom-Server)
> > |
> > = OU_Zentrale (Group-Policy-Zentrale)
> > | |
> > | = User-1 (User)
> > | = User-2 (User)
> > | = PC1 (PC)
> > |
> > = OU_Fibu (Group-Policy -Fibu)
> > | |
> > | = User-3 (User)
> > | = User-4 (User)
> > | = PC2 (PC)
> > |
> > = OU_TServer (Group-Policy-Terminal-Server)
> > |
> > = GR-TServer (Secure-Group)
> > = Srv-TServer (Terminal-Server)
> >
> > User-1 - User-4 are member of GR-TServer. In ervery OU "Zentrale"
> > and "Fibu" we have group-policies for user's and pc's. In OU TServer the
> > transmission for the group-policies is switched of.
> >
> > The TServer is only a member-server; Loopback is set to
> > "replace"; the security-rights for the group GR-TServer and the TServer
> > are
> > set to "read" and take over of "group-policy".
> >
> > Every things works fine for over a year but now we have the following
> > problem:
> >
> > If a user is logged an via Remote-Desktop to the Terminal-Server the
> > group-policy of his OU (Fibu or Zentrale) works and not the policiy of
> > OU_Tserver. When we add a user directly to the OU OU_Tserver erverything
> > is
> > ok.
> >
> > --
> > Technik - MoDa
> >
> >
>
>
>
.