GPO for one machine

From: Jeremy Rodriguez (jeremyrodriguez_at_cmsmechanical.com)
Date: 09/09/03

  • Next message: Zachary Mutrux: "RE: Disable USB on a per user basis?"
    To: "Focus-Ms" <focus-ms@securityfocus.com>
    Date: Tue, 9 Sep 2003 14:34:38 -0400
    
    

    I have one machine setup with Terminal Server. I have setup a limited
    desktop using a policy (GPO). I want to be able to have domain admins login
    and get all menus/programs, while the rest of the users get the limited
    desktop. As I have it now whenever anyone logs in to the box they all get
    the limited desktop no matter if they are a domain admin. How do I fix this?
    I have set it up so it only applies to this machine (loopback) and the
    domain admins security box is set not to apply group policy.

    ---------------------------------------------------------------------------
    KaVaDo provides the first and only integrated Web application scanner and
    firewall security suite that prevent Web applications attacks, the most
    common form of online exploitation. Download a FREE whitepaper on Security Policy Automation for Web Applications.
    http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
    ---------------------------------------------------------------------------


  • Next message: Zachary Mutrux: "RE: Disable USB on a per user basis?"

    Relevant Pages

    • Re: Active directory Group Policy (Win2k)
      ... When I enforce the policy onto the computers in the new OU, ... Domain Admins so the Domain Admins cannot view ... workstations, to access Microsoft Office. ...
      (microsoft.public.security)
    • Re: administrator locked out of SBS 2003
      ... The Domain Admins group was a member of ... included in the "Deny log on locally" local security policy settings. ... Select "All users except local administrators" ... That allowed the installation of VMware server to complete. ...
      (microsoft.public.windows.server.sbs)
    • Re: Clarification Needed
      ... My plan was to create 2 GPO's one User Level and one Domain Admin GPO. ... Is there any problem removing and in line with the above thinking, add domain users to the User GPO and domain admins to the Domain Admins GPO. ... You can alter the NFTS permissions of the Group Policies by accessing the tab "Security" at the properties of the Policy. ... If a group of users shall not apply/overtake a Group Policy, simple add a "Deny Group Policy" permission to the group... ...
      (microsoft.public.windows.group_policy)
    • Re: Access to stop/start services.
      ... These permissions are only exposed in Group Policy. ... Open the Active Directory Users and Computers snap-in. ... Grant the System account and Domain Admins Full Control. ...
      (microsoft.public.windows.server.general)