How to exclude a user from loopback policy
we create loopback policy our windows 2008 r2 rds. works fine. however, want deny policy users. check deny in apply group. sown screenshot.
however, computer policy still applies user (user policy denied). post gpresult here.
computer settings
------------------
last time group policy applied: 5/20/2013 @ 4:11:00 pm
group policy applied from: 2008dc
group policy slow link threshold: 500 kbps
domain name: domain
domain type: windows 2000
applied group policy objects
-----------------------------
rds client policy
default domain policy
the following gpos not applied because filtered out
-------------------------------------------------------------------
webhawk ad
filtering: disabled (gpo)
local group policy
filtering: not applied (empty)
user settings
--------------
last time group policy applied: 5/20/2013 @ 4:11:36 pm
group policy applied from: 2008dc
group policy slow link threshold: 500 kbps
domain name: domain
domain type: windows 2000
applied group policy objects
-----------------------------
default domain policy
webhawk ad
local group policy
the following gpos not applied because filtered out
-------------------------------------------------------------------
vircom addin client
filtering: denied (security)
rds client policy
filtering: denied (security)
bob lin, mvp, mcse & cne networking, internet, routing, vpn troubleshooting on
how setup windows, network, vpn & remote access on
hi,
the user group policy loopback processing mode policy setting advanced option intended keep configuration of computer same regardless of logs on. loopback group policy defined in computer ou , apply computer account, computer level group policy.
there 2 options available loopback policy:
merge mode: in mode, list of gpos user gathered during logon process. then, list of gpos computer gathered. next, list of gpos computer added end of gpos user. result, computer’s gpos have higher precedence user’s gpos.
replace mode: in mode, list of gpos user not gathered. instead, list of gpos based on computer object used. user configuration settings list applied user.
according definition, loopback group policy used deploy “user” group policy based on computer object, user policy main purpose. can use “deny” security policy prevent user apply user policy, can’t prevent computer account applying computer policy.
for requirement, isolate computer policy loopback policy.
for more information please refer following ms articles:
using loopback processing configure user settings
http://technet.microsoft.com/en-us/library/cc757470(v=ws.10).aspx
hope helps!
technet subscriber support
if technet subscription user , have feedback on our support quality, please send feedback here.
lawrence
technet community support
Windows Server > Group Policy
Comments
Post a Comment