N
Noncentz
Guest
Morning,
I am trying to lockdown the desktop on my terminal servers via a GPO called
Terminal Services Lockdown. I used this guide mainly to get find what I
needed. The gpo is applied to the 2 TS servers as well as a TS user group.
When I log in a testuser I run gpresult and find that my computer settings
are not applying but the user settings are. Any thoughts??
http://www.msterminalservices.org/articles/Managing-Terminal-Services-Group-Policy.html
Also I remember there being a white paper out about GPO on Terminal
services, anyone know of this??
----------------my gpresults from testuser
Microsoft (R) Windows (R) Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001
Created On 6/4/2008 at 8:22:59 AM
RSOP data for MCCOYSALES\testuser on MCSVR03 : Logging Mode
------------------------------------------------------------
OS Type: Microsoft(R) Windows(R) Server 2003, Enterprise
Edition
OS Configuration: Member Server
OS Version: 5.2.3790
Terminal Server Mode: Application Server
Site Name: N/A
Roaming Profile:
Local Profile: C:\Documents and Settings\testuser
Connected over a slow link?: No
USER SETTINGS
--------------
CN=TestUser,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=mccoysales,DC=local
Last time Group Policy was applied: 6/4/2008 at 8:22:21 AM
Group Policy was applied from:
Group Policy slow link threshold: 500 kbps
Domain Name:
Domain Type: Windows 2000
Applied Group Policy Objects
-----------------------------
McCoy Wireless LAN Policy
Terminal Services Lockdown
Default Domain Policy
Local Group Policy
The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Small Business Server Remote Assistance Policy
Filtering: Disabled (GPO)
Small Business Server Internet Connection Firewall
Filtering: Denied (WMI Filter)
WMI Filter: PreSP2
Small Business Server - Windows Vista policy
Filtering: Denied (WMI Filter)
WMI Filter: Vista
Small Business Server Client Computer
Filtering: Not Applied (Empty)
Small Business Server Domain Password Policy
Filtering: Not Applied (Empty)
Small Business Server Windows Firewall
Filtering: Denied (WMI Filter)
WMI Filter: PostSP2
EnlightenUsers
Filtering: Not Applied (Empty)
Small Business Server Lockout Policy
Filtering: Disabled (GPO)
WSUS Client Policy
Filtering: Denied (Security)
The user is a part of the following security groups
---------------------------------------------------
Domain Users
Everyone
Remote Desktop Users
BUILTIN\Users
REMOTE INTERACTIVE LOGON
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users
This Organization
LOCAL
Wireless Users
Prophet21_Users
CERTSVC_DCOM_ACCESS
I am trying to lockdown the desktop on my terminal servers via a GPO called
Terminal Services Lockdown. I used this guide mainly to get find what I
needed. The gpo is applied to the 2 TS servers as well as a TS user group.
When I log in a testuser I run gpresult and find that my computer settings
are not applying but the user settings are. Any thoughts??
http://www.msterminalservices.org/articles/Managing-Terminal-Services-Group-Policy.html
Also I remember there being a white paper out about GPO on Terminal
services, anyone know of this??
----------------my gpresults from testuser
Microsoft (R) Windows (R) Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001
Created On 6/4/2008 at 8:22:59 AM
RSOP data for MCCOYSALES\testuser on MCSVR03 : Logging Mode
------------------------------------------------------------
OS Type: Microsoft(R) Windows(R) Server 2003, Enterprise
Edition
OS Configuration: Member Server
OS Version: 5.2.3790
Terminal Server Mode: Application Server
Site Name: N/A
Roaming Profile:
Local Profile: C:\Documents and Settings\testuser
Connected over a slow link?: No
USER SETTINGS
--------------
CN=TestUser,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=mccoysales,DC=local
Last time Group Policy was applied: 6/4/2008 at 8:22:21 AM
Group Policy was applied from:
Group Policy slow link threshold: 500 kbps
Domain Name:
Domain Type: Windows 2000
Applied Group Policy Objects
-----------------------------
McCoy Wireless LAN Policy
Terminal Services Lockdown
Default Domain Policy
Local Group Policy
The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Small Business Server Remote Assistance Policy
Filtering: Disabled (GPO)
Small Business Server Internet Connection Firewall
Filtering: Denied (WMI Filter)
WMI Filter: PreSP2
Small Business Server - Windows Vista policy
Filtering: Denied (WMI Filter)
WMI Filter: Vista
Small Business Server Client Computer
Filtering: Not Applied (Empty)
Small Business Server Domain Password Policy
Filtering: Not Applied (Empty)
Small Business Server Windows Firewall
Filtering: Denied (WMI Filter)
WMI Filter: PostSP2
EnlightenUsers
Filtering: Not Applied (Empty)
Small Business Server Lockout Policy
Filtering: Disabled (GPO)
WSUS Client Policy
Filtering: Denied (Security)
The user is a part of the following security groups
---------------------------------------------------
Domain Users
Everyone
Remote Desktop Users
BUILTIN\Users
REMOTE INTERACTIVE LOGON
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users
This Organization
LOCAL
Wireless Users
Prophet21_Users
CERTSVC_DCOM_ACCESS