N
Nick
Can you please help resolve a loopback issue, my policy works but doesn't do
the loopback element. I only want the policy to be applied when users logs
into to Terminal server/Citrix servers OU but the policy is also being
applied to their workstation.
I have followed the recommendation from these Microsoft knowledgebase
articles:
http://support.microsoft.com/kb/231287 - Loopback processing of Group Policy
http://support.microsoft.com/kb/260370 - How to apply Group Policy objects
to Terminal Services servers
http://support.microsoft.com/kb/278295 - How to lock down a Windows Server
2003 or Windows 2000 Terminal Server session
I will create a simple loopback policy and I will go through this
step-by-step and see if you can see if I'm doing anything wrong.
Ok first of all here is our domain: (Single domain model and also I've
blocked inheritance on the Citrix OU)
ACME root
I
ACME.COM Domain
I__ACME Country A
I__ACME Country B
I__ACME Country UK
I__Users OU
I__Groups OU
I__Citrix OU
I__Computers OU
I__Laptops OU
I__Servers OU
Users will login to Citrix OU and policy will be applied to anyone in
Security Group
"UK Users Citrix Server Policy"
Open GPMC.MSC > Goto Citrix OU > right-click > Create and Link GPO Here >
Name new GPO "ACME UK Citrix Server Policy > OK >
select > Scope > Security Filtering > Add "UK Users Citrix Server Policy"
and remove Authenticated Users.
Right-click policy > Edit >
Computer Configuration > Administrative Templates > System >Group Policy >
User Group Policy loopback > processing mode > Enabled > Mode Replace > OK
User configuration > Administrative Templates > Start Menu and Taskbar >
Remove Run menu from Start Menu > Enabled > OK
Goto > Users OU > Right-click > Link an Existing GPO > select ACME UK Citrix
Server Policy > OK
Login to Citrix as user member of security group "UK Users Citrix Server
Policy" and run command removed.
Login to workstation as user member of security group "UK Users Citrix
Server Policy" and run command removed.
Why is policy being applied to the workstation, I only want it applied to
Citrix OU
Also how is the policy to know to apply to Citrix OU only and not to the
workstation
Many thanks for taking the time to read this and for your comments.
the loopback element. I only want the policy to be applied when users logs
into to Terminal server/Citrix servers OU but the policy is also being
applied to their workstation.
I have followed the recommendation from these Microsoft knowledgebase
articles:
http://support.microsoft.com/kb/231287 - Loopback processing of Group Policy
http://support.microsoft.com/kb/260370 - How to apply Group Policy objects
to Terminal Services servers
http://support.microsoft.com/kb/278295 - How to lock down a Windows Server
2003 or Windows 2000 Terminal Server session
I will create a simple loopback policy and I will go through this
step-by-step and see if you can see if I'm doing anything wrong.
Ok first of all here is our domain: (Single domain model and also I've
blocked inheritance on the Citrix OU)
ACME root
I
ACME.COM Domain
I__ACME Country A
I__ACME Country B
I__ACME Country UK
I__Users OU
I__Groups OU
I__Citrix OU
I__Computers OU
I__Laptops OU
I__Servers OU
Users will login to Citrix OU and policy will be applied to anyone in
Security Group
"UK Users Citrix Server Policy"
Open GPMC.MSC > Goto Citrix OU > right-click > Create and Link GPO Here >
Name new GPO "ACME UK Citrix Server Policy > OK >
select > Scope > Security Filtering > Add "UK Users Citrix Server Policy"
and remove Authenticated Users.
Right-click policy > Edit >
Computer Configuration > Administrative Templates > System >Group Policy >
User Group Policy loopback > processing mode > Enabled > Mode Replace > OK
User configuration > Administrative Templates > Start Menu and Taskbar >
Remove Run menu from Start Menu > Enabled > OK
Goto > Users OU > Right-click > Link an Existing GPO > select ACME UK Citrix
Server Policy > OK
Login to Citrix as user member of security group "UK Users Citrix Server
Policy" and run command removed.
Login to workstation as user member of security group "UK Users Citrix
Server Policy" and run command removed.
Why is policy being applied to the workstation, I only want it applied to
Citrix OU
Also how is the policy to know to apply to Citrix OU only and not to the
workstation
Many thanks for taking the time to read this and for your comments.