How to exclude a user from loopback policy


we create loopback policy our windows 2008 r2 rds. works fine. however, want deny policy users. check deny in apply group. sown screenshot.

however, computer policy still applies user (user policy denied). post gpresult here.

computer settings

------------------

   

    last time group policy applied: 5/20/2013 @ 4:11:00 pm

    group policy applied from:      2008dc

    group policy slow link threshold:   500 kbps

    domain name:                        domain

    domain type:                        windows 2000

    applied group policy objects

    -----------------------------

        rds client policy

        default domain policy

    the following gpos not applied because filtered out

    -------------------------------------------------------------------

        webhawk ad

            filtering:  disabled (gpo)

        local group policy

            filtering:  not applied (empty)

user settings

--------------

   

    last time group policy applied: 5/20/2013 @ 4:11:36 pm

    group policy applied from:      2008dc

    group policy slow link threshold:   500 kbps

    domain name:                        domain

    domain type:                        windows 2000

    applied group policy objects

    -----------------------------

        default domain policy

        webhawk ad

        local group policy

    the following gpos not applied because filtered out

    -------------------------------------------------------------------

        vircom addin client

            filtering:  denied (security)

        rds client policy

            filtering:  denied (security)


bob lin, mvp, mcse & cne networking, internet, routing, vpn troubleshooting on

http://www.chicagotech.net

how setup windows, network, vpn & remote access on

http://www.howtonetworking.com

hi,

the user group policy loopback processing mode policy setting advanced option intended keep configuration of computer same regardless of logs on. loopback group policy defined in computer ou , apply computer account, computer level group policy.

there 2 options available loopback policy:

merge mode: in mode, list of gpos user gathered during logon process. then, list of gpos computer gathered. next, list of gpos computer added end of gpos user. result, computer’s gpos have higher precedence user’s gpos.

replace mode: in mode, list of gpos user not gathered. instead, list of gpos based on computer object used. user configuration settings list applied user.

according definition, loopback group policy used deploy “user” group policy based on computer object, user policy main purpose. can use “deny” security policy prevent user apply user policy, can’t prevent computer account applying computer policy.

for requirement, isolate computer policy loopback policy.

for more information please refer following ms articles:

using loopback processing configure user settings
http://technet.microsoft.com/en-us/library/cc757470(v=ws.10).aspx

hope helps!
technet subscriber support
if
technet subscription user , have feedback on our support quality, please send feedback here.


lawrence

technet community support



Windows Server  >  Group Policy



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file