Problem Deploying and removing Remoteapps based on group membership
i building remoteapp farm based on windows 2008 r2. every remoteapp have created user gpo targeted security group has same name remoteapp. way can deploy remoteapp based on group membership. working had create addition gpo settings.
1. create gpo created "remotepackages" folder in program files of client. user had no permissions create files in folder.
2. create gpo changes permissions of folder user has write permissions in folder.
3. set gpo prio gpo ntfs changes runs after folder has created, prevents computer reboot.
4. create gpo (user) deploying remoteapp msi, , set option install @ logon, , uninstall when out of scope.
5. remoteapp msi, creates file extension associations, creates .rdp , .ico file in "remotepackages" , places shortcuts on desktop , startmenu.
this installs remote app when user logs on has rights use example word.
so far installing remoteapps.
so far good.
but:
when decide user x has no rights anymore use word, remove him security group word, @ next logon remoteapp being uninstalled....nice ;-)
and think, whats problem......
the problem is:
the user uninstalled msi has deleted .rdp. , .ico file "remotepackes" folder in program files!
so other user logged in on computer gets, "dead shortcuts".
i tried change ntfs permissions on "remotepackages folder" no 1 has delete permissions.
even, administrator , system have no delete rights anymore. still files deleted system.
if last remoteapp uninstalled, de remotepackages folder deleted.
- down know how solve this?
- account software uninstalled?
i tying not change default msi files unless absolutely necessary. trying keep network free custom made components.
can assist me this?
thanks!
marcel
hi,
thank posting.
from post, understanding on issue is: account needed uninstall software. if misunderstand question, please let me know.
in case, think there wrong permission settings of “remotepackes”. please perform following steps confirm whether permission setting meets request
to set, view, change, or remove special permissions files , folders:
1. click start, click my computer, , locate file or folder want set special permissions.
2. right-click file or folder, click properties, , click security tab.
3. click advanced, , follow 1 of the steps below:
o to set special permissions additional group or user, click add, , in name box, type name of user or group, , click ok.
o to view or change special permissions existing group or user, click name of group or user, , click edit.
o to remove existing group or user , special permissions, click name of group or user, , click remove. if remove button unavailable, click clear inherit parent permission entries apply child objects. include these entries explicitly defined here check box, click remove, , skip steps 4 , 5.
4. in permissions box, click select or click clear appropriate allow or deny check box.
5. in apply onto box, click folders or subfolders want these permissions applied.
6. to configure security subfolders , files not inherit these permissions, click clear apply these permissions objects and/or containers within container only check box.
7. click ok 2 times, , click ok in advanced security settings foldername box, foldername folder name.
meanwhile, suggest can use assignment feature instead of using gpo control permission. can narrow down issue.
assign domain users , domain groups remoteapp program
http://technet.microsoft.com/en-us/library/dd851539.aspx
hope suggestions provided above help.
                                                                          Windows Server                                                     >                                                                 Remote Desktop Services (Terminal Services)                                                                           
 
 
  
 
Comments
Post a Comment