New Group Policy not working on 2008 RDS in 2012 Domain - Security Filtering problem?
we have windows 2008 r2 rds in windows 2012r2 domain. want lockdown 2008 rds domain users have added new security group--named "data collection users". these users "domain users" , login 2008 rds using windows xp sp3 machines run specific application -they not use local desktops anything. added group local rdu group on rds. not have other users login rds through terminal, including domain admins.
so far have done these steps:
- on dc, created new ou (called terminal servers) and moved rds it.
- opened group policy on dc, , under gp objects, created new policy called "ts users lockdown".
- linked policy ou.
- under security filtering removed authenticated users, added rds computer account (called qs2), added "data collection users" , chose allow "read" , "apply policy"
- under security filtering, domain admins, chose deny "apply group policy"
- we edited policy (under computer configuration>at>sys>gp) to enable loopback processing - replace mode.
- we first tested policy trying remove "run" startup menu , "prohibit access control panel".
- we ran group policy force update within gp management - ran successfully.
- we did not reboot rds.
- neither of settings tried in step 7 worked. why not?
here images security filtering:
hi,
restart rdsh server, since enabled loopback mode on.
-tp
Windows Server > Remote Desktop Services (Terminal Services)
Comments
Post a Comment