New Group Policy not working on 2008 RDS in 2012 Domain - Security Filtering problem?


we have windows 2008 r2 rds in windows 2012r2 domain. want lockdown 2008 rds domain users have added new  security group--named "data collection users". these users "domain users" , login 2008 rds using windows xp sp3 machines run specific application -they not use local desktops anything. added group local rdu group on rds.  not have other users login rds through terminal, including domain admins.

so far have done these steps:

  1. on dc, created new ou (called terminal servers) and moved rds it.
  2. opened group policy on dc, , under gp objects, created new policy called "ts users lockdown".
  3. linked policy ou.
  4. under security filtering removed authenticated users, added rds computer account (called qs2), added "data collection users" , chose allow "read" , "apply policy"
  5. under security filtering, domain admins, chose deny "apply group policy"
  6. we edited policy (under computer configuration>at>sys>gp) to enable loopback processing - replace mode.
  7. we first tested policy trying remove "run" startup menu , "prohibit access control panel".
  8. we ran group policy force update within gp management - ran successfully.
  9. we did not reboot rds.
  10. neither of settings tried in step 7 worked.  why not?

here images security filtering:

hi,

restart rdsh server, since enabled loopback mode on.

-tp



Windows Server  >  Remote Desktop Services (Terminal Services)



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS