loopback processing mode

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Guest
Archived from groups: microsoft.public.win2000.security (More info?)

I needed loopback processing mode to apply GPO's to
terminalserverusers, so if they log on to a hard disk
machine they don't get the GPO. However if domain
administrator logs on to a terminalserver, he gets the GPO
as well and I don't want that. We tried to deny apply
group policy on domain admins but that didnt work. Has
anyone a clue???

gr. Robert Schaaf
 
Archived from groups: microsoft.public.win2000.security (More info?)

Try applying the deny permission for administrators to the GPOs that are in the
container that the TS resides. Gpresult can be helpful in troubleshooting Group
Policy problems as it will show what policies apply to a user and the last time they
were applied. --- Steve


"R. Schaaf" <scf@hesasd.nl> wrote in message
news:1ddf701c45450$1ee09c90$a001280a@phx.gbl...
> I needed loopback processing mode to apply GPO's to
> terminalserverusers, so if they log on to a hard disk
> machine they don't get the GPO. However if domain
> administrator logs on to a terminalserver, he gets the GPO
> as well and I don't want that. We tried to deny apply
> group policy on domain admins but that didnt work. Has
> anyone a clue???
>
> gr. Robert Schaaf