Re: Terminal server lockdown



Check this article:

816100 - How To Prevent Domain Group Policies from Applying to
Administrator Accounts and Selected Users in Windows Server 2003
http://support.microsoft.com/?kbid=816100

_________________________________________________________
Vera Noest
MCSE, CCEA, Microsoft MVP - Terminal Server
TS troubleshooting: http://ts.veranoest.net
SQL troubleshooting: http://sql.veranoest.net
___ please respond in newsgroup, NOT by private email ___


=?Utf-8?B?TWFyayBCb3dsZXM=?=
<MarkBowles@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote on 07 apr 2006 in
microsoft.public.windows.terminal_services:

I have the same issue. Where do you deny permissions for
administrator?

Mark

"DJ" wrote:

Gee wiz, that is so obvious. I have it so drilled in my head to
avoid Deny permissions that I didn't even consider it. Thanks.

"Richard Gadsden" wrote:

DJ wrote:
I'm putting together a GPO for locking down terminal server
user sessions. I created a loopback policy that enforces
the user settings in the terminal server's policy. However,
the settings also apply to administrators that login to the
server. How do I prevent these settings from applying to
administrators?

Set the permission on the policy to deny it to
administrators.

--
Richard Gadsden
"I disagree with what you say, but I will defend to the death
your right to say it" - Attributed to Voltaire
.



Relevant Pages

  • Re: administrator locked out of SBS 2003
    ... Restriction Policies node and select New Software Restriction Policy ... Select "All users except local administrators" ... This is a known issue when installing VMware server 2.0, ... the installation kept ...
    (microsoft.public.windows.server.sbs)
  • Re: administrator locked out of SBS 2003
    ... This is a known issue when installing VMware server 2.0, ... Deleting a policy does not necessarily undo the settings that were ... selected "applies to all users except administrators" That allowed ...
    (microsoft.public.windows.server.sbs)
  • Re: administrator locked out of SBS 2003
    ... The Domain Admins group was a member of the Remote Operators ... My suspicion is that the policy change 'tattooed' the ... Select "All users except local administrators" ... That allowed the installation of VMware server to complete. ...
    (microsoft.public.windows.server.sbs)
  • Re: Restrict to 1 program
    ... Can I create the policy, apply it to the ... You can link a GPO to a site, or a domain, or an OU, and it will be ... MCSE, CCEA, Microsoft MVP - Terminal Server ... it doesn't apply to Administrators: ...
    (microsoft.public.windows.terminal_services)
  • Re: Can not install applications using any admin account
    ... You could try if it works without those restrictive policy ... I also have a vbscript running at logon ... these Computer Policy Settings: ... restrictions is *not* applied to Administrators. ...
    (microsoft.public.windows.terminal_services)