Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
Home
Discussion GroupsWindows Server 2003Windows 2000Windows NTSmall Business ServerVirtual ServerExchange ServerIISHost Integration ServerISA ServerSMSWSUSMOMWindows Media ServerSecurityCertification
Related Topics
SQL ServerMS WindowsMS OfficePC HardwareMore Topics ...

Windows Server Forum / Windows Server 2003 / Group Policy / July 2008

Tip: Looking for answers? Try searching our database.

Preventing group policy when using remoteapp

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
Saucer Man - 25 Jul 2008 15:51 GMT
We are going to start using terminal server on Windows 2008.  The terminal
server should pull down the group policies like any other server.  However,
when a user logs onto the terminal server from a remote session, i.e,
remoteapp, group policies should not be processed.  Right now, if I launch a
remoteapp from my PC, I see that my group policies are running again.  How
do I prevent this?

Signature

Thanks!

Florian Frommherz [MVP] - 25 Jul 2008 18:20 GMT
Howdie!

> We are going to start using terminal server on Windows 2008.  The terminal
> server should pull down the group policies like any other server.  However,
> when a user logs onto the terminal server from a remote session, i.e,
> remoteapp, group policies should not be processed.  Right now, if I launch a
> remoteapp from my PC, I see that my group policies are running again.  How
> do I prevent this?

you can try activating group Policy's loopback processing mode. It's
there for Terminal Servers. It's got two modes: Replace and Merge. When
choosing "Replace" mode, Group Policy applies all policies that are
linked to the Terminal Server's OU to the user logging in there. It
overwrites the user's "user configuration" portion so to speak.

Check:
http://support.microsoft.com/kb/231287/en-us
http://support.microsoft.com/kb/260370/en-us
http://technet2.microsoft.com/windowsserver/en/library/abe2b1a9-975f-4b2f-b771-9
e6a903e97db1033.mspx?mfr=true


cheers,

Florian
Signature

Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste

Saucer Man - 25 Jul 2008 19:54 GMT
> Howdie!
> you can try activating group Policy's loopback processing mode. It's there
[quoted text clipped - 11 lines]
>
> Florian

I thought about this but the policies that are associated with the user
account that logs onto the terminal server are still run.  The loopback only
replaces the Computer Configuration.
Florian Frommherz [MVP] - 26 Jul 2008 12:25 GMT
Howdie!

> I thought about this but the policies that are associated with the user
> account that logs onto the terminal server are still run.  The loopback only
> replaces the Computer Configuration.

Make sure you run Loopback in "Replace" mode. That replaces the "User
Configuration" settings that apply to the user with the "User
Configuration" settings that apply to the Terminal Servers.

cheers,

Florian
Signature

Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste

Saucer Man - 28 Jul 2008 13:51 GMT
Ahhh...I see.  I will give this a shot.  Thanks.

> Howdie!
>
[quoted text clipped - 9 lines]
>
> Florian
Saucer Man - 28 Jul 2008 14:37 GMT
Well I tried creating a policy with Loopback Replace Mode but the users
policy is still running.  I can tell because the users policy is running a
script and I can see this script error when I try to logon to a RemoteAPP.
I linked this policy to the OU where the terminal server resides.

> Howdie!
>
[quoted text clipped - 9 lines]
>
> Florian
Saucer Man - 28 Jul 2008 15:19 GMT
OK.  It's working now.  I think it needed time.  Thanks.

> Well I tried creating a policy with Loopback Replace Mode but the users
> policy is still running.  I can tell because the users policy is running a
[quoted text clipped - 14 lines]
>>
>> Florian
southpaw - 01 Aug 2008 00:08 GMT
Thanks
>> Howdie!
>> you can try activating group Policy's loopback processing mode. It's
[quoted text clipped - 15 lines]
> account that logs onto the terminal server are still run.  The loopback
> only replaces the Computer Configuration.
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2008 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.