GPOs for RD Users
we have windows 2008 r2 rdweb server, 2 window 2008 r2 rd servers remote apps.
users go rdweb server run published apps.
we have 1 app have run rdp app. starts rd session, users log rd server , run app
i know how can set domain gpo(s) make sure when rdp app starts users can not doing following:
1. see control panel
2. see or run internet explorer
3. can select log off when completed
also, don't want effect domain admins.
thank you
when say:
we have 1 app have run rdp app.
i assuming not using rd app, rather full desktop session 1 program?
the quick , dirty way need include "alternate shell" property in rdp config file. way user full session, explorer not load, specified app.
however, if want preserve basic explorer functionality have implement gpo rd session host farm. acheve above mentioned settings, use following gpo options.
1 - user configuration \ policies \ administrative templates \ control panel \ prohibit access control panel
2 - not believe there built-in gpo prevent access ie. however, can uninstall server with:
dism /online /disable-feature /featurename:internet-explorer-optional-amd64.
3 - user configuration \ policies \ administrative templates \ start menu , taskbar \ remove , prevent access shutdown, restart, sleep , hibernate commands.
Windows Server > Remote Desktop Services (Terminal Services)
Comments
Post a Comment