Deploy an MSI for Terminal server users

Hello,
I have faced with the issue which I can't resolve on my own - the MSI is not run when the user logs on. Moreover, I don't see the GPO applied in the Group Policy Results for the user:
Here is what I did on the server side:
1. Created a separate OU for testing (actually, it doesn't work if I apply a policy at the domain level).
2. Created a test user account.
3. Created a shared folder (Read for everyone). Made sure that an user can read files from that folder.
4. Placed the msi file in the shared folder. Before doing that, I tested the installer in the fields running the "msiexec.exe /i /s" command.
5. Created a new Group Policy object where I added a new software installation at the User Configuration node. I specified the filepath in the following format -
\\server\folder\msifile . Assigned. Chose the
Install this application at logon. Maximum (User Interface).
6. Linked the GPO to the OU where the user resides.
7. The Settings in the GPO apply only for the specified user. Also I checked permissions on the Delegation tab for the user - Read / Apply Group Policy are selected.
Here is how it looks like:
Most probably I tried to adjust some properties for troubleshooting. But nothing helped.
When I logon as a domain user I see that the GPO was applied successfully (gpresult.exe confirms). But I don't see any installation wizard, nor MSI installed. The result is shown on the first screenshot.
I even don't get any errors in the Group Policy log. I have a feeling that user settings in my GPO are ignored by the system. Why does it happen? Is there any setting I missed setting up a new GPO?
P.S. I have tried turning on various Group Policy settings located in the Administrative Templates / System / Group Policy.

Hi Eugene,
Based on your description, to make sure that this is not caused by fast logon optimization feature, we can enable the following setting:
Computer Configuration\Administrative Templates\System\Logon\ Always wait for the network at computer startup and logon
After enabling this setting and updating the policy, we can try logging off and logging on again to see if it works.
Regarding fast logon optimization, the following article can be referred to for more information.
Description of the Windows Fast Logon Optimization feature
http://support.microsoft.com/kb/305293/en-us
Hope it helps.
Best regards,
Frank Shen

Similar Messages

  • Outlook is running to slow for terminal server users

    All tried but no luck .thanks

    Outlook is running to slow for terminal server users and very slow updating inbox. Can anyone suggest how can i increase speed for the users ?
    Office 2013
    exchange 2010
    This topic first appeared in the Spiceworks Community

  • Adding another exchange account Outlook 2013 Pro Plus for terminal Server users

    Really hoping someone can offer some advice on this one as I have wasted far to many cycles trying to figure this out.
     Company I work for recent purchased another company and we are in the process of bringing them into our network.  They currently run a a 2008 R2 terminal server where all users connect to for there day to day work.  A number of applications
    are installed including Office 2013.
    All users have Outlook 2013 configured to access their exchange server for email and this works fine.
    The first step in bringing them into our fold is to add an email account for Our Exchange  server without removing their existing exchange configuration or Outlook Profile.  So the one profile will have both exchange accounts listed and they can
    continue to get email from their server but as well email from our domain.
    I created a MSP file and tested pushing this out using PDQ Deploy to a few workstations here in our office and it works fine.  I then started to work on deploying in their environment.  PDQ Deploy will not work as they are all terminal Services
    Clients.  So I tried to push out via GPO.  I created the GPO Initially wanting to use a package and apply that GPO to an AD group.  However it will not let me deploy a MST as a package.  So I then tried moving it to a script that would
    run at logon.  That too is not working.
    I know I could enter install mode then run the MSIEXEC.EXE \config.MSP but that takes away the ability to control the role out.
    Any other ideas on how to get this done.

    Using the MSPfile method would require the logged-on user to have the necessary Windows permissions to run setup.exe, and on an RDS/TS Session Host, that's not likely to be available. (since it's not a great idea to give end-users those permissions on a
    shared system like RDS/TS)
    But you might be able to do it with a PRF file and an Outlook launch command, like this?
    http://technet.microsoft.com/en-us/library/cc179062(v=office.15).aspx
    Don
    (Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
    This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

  • Logon rejected for Unable to obtain Terminal Server User Configuration. Error: Not enough resources are available to complete this operation.

    Error: Logon rejected for  Unable to obtain Terminal Server User Configuration. Error: Not enough resources are available to complete this operation.
    The problem is that the SharePoint server will
    function just fine for a week or so and then suddenly when a new user tries
    to log on they get an error message indicating that not enough resources areavailable to
    log them on and also user will to credential prompt while accessing share point site . 
    Raj

    Hi,
    According to the error message, please use performance monitor to diagnose if it is a memory-related bottleneck and you can use the counters of the memory part in the article below:
    https://technet.microsoft.com/en-us/magazine/2008.08.pulse.aspx
    In addition, it may be due to thousands of open connections to the server are in a TIME_WAIT state. You can run "netstat -an" command on the affected server and client. If you see mutiple connections in the TIME_WAIT state, you can follow the article
    to increase the number of TCP/IP connections:
    https://msdn.microsoft.com/en-us/library/ee377084(v=bts.70).aspx
    Furthermore, if you are running windows server 2003, please make sure that you have installed the KB 948496 and stop all services that you don't need.
    Best regards,
    Susie
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • Sequencing for terminal server

    Hi,
    Is there any prereq we should take into account when creating an app for terminal server (Windows 2008 R2)?
    The problem we are facing now is that App-v packages are working correctly for 1 user but others (on the same terminal server) don't see the shortcut. If we copy past the screenshot to their menu it works fine.
    Please advise.
    J.
    Jan Hoedt

    I suppose it's SP1 for SCCM 2012, as this adds App-V 5 support.
    Do you target machines or users in your deployment type? 
    Do you do any 'bad tricks' with the start menu (like redirecting it)?
    Falko
    Twitter
    @kirk_tn   |   Blog
    kirxblog   |   Web
    kirx.org   |   Fireside
    appvbook.com

  • Group Policy design for Terminal Server

    Hi, I am mixed about group policy design for Terminal server
    My Infrastructure is so;
    Zone
          ->Department
                       ->User
                       ->Computers
          ->Department
                       ->User
                       ->Computers
          ->Department
                       ->User
                       ->Computers
    Server
           ->OtherServer
            ->TerminalServer (TerminalComputersGPO)
    I create two group policy for user and for terminal server computers (security filtered for Terminal_Users)
    I want to use terminal server user policy but it must effect
    just in terminal computers. not TS user's computers. what i must do? where i must locate it?
    Please click "Vote As Helpful" if it is helpful for you and "Propose as Answer"

    Hi Davut EREN - TAT,
    According to your description, you would like
    terminal server user policy applying to users which log on to terminal computers. Right?
    As MuhammadUmar's suggestion, you can use Loopback in replace mode. The GPO list for the user is replaced in its entirety by the GPO list that is already obtained for the computer at computer startup.
    In the real work environment Loopback processing of Group Policy is usually used on Terminal Servers. For example we have users with enabled folder redirection settings, but we do not want these folder redirection to work when the users log on to the
    Terminal Server, in this case we enable Loopback processing of Group s Computer account and do not enable the folder redirection settings.
    For more information about this policy, please refer to the following articles:
    Loopback processing with merge or replace
    Loopback processing of Group Policy
    Regards,
    Lany Zhang

  • Terminal Server User license file not found or User ID not matched.

    Hi,
    I recently went for the Process Runner, downloaded trial version and wanted to work with Ides system, but at the very first step the system throws the following error:
    "Terminal Server User license file not found or User ID not matched.
    and the details are as follows:
    Process Runner 2008
    Version : 4.20.10
    Supported file version: 7.3
    Current Framework: 2.0.50727.42
    User Name: Demo User
    Licensed  To: Demo Company
    Product Id : PR-ALL-DR-MTH-CU
    Full Version : 4.20.10.9579
    Current UserID : Administrator
    License Type : Evaluation/Demo License
    Evaluation Days : 1 of 30
    Licensed Uses : 5 of 15
    Expiration Date : 12/31/2011
    COMPANY : Demo Company
    MAX_ROWS : 30
    MAX_THREADS : 3
    USER : Demo User
    Current Node Id : DAAB-AA43-58DB-00DB-4862
    Max Instances Allowed : N/A
    OS-Office culture info : en-US | en-US | en-US | en-US
    C-Info : en-US
    Computer : SAPSERVER
    Current Domain : WORKGROUP
    OS : Microsoft Windows NT 5.2.3790 Service Pack 1
    AppPath : D:\Vijj downloaded\Process Runner
    MyDocPath : C:\Documents and Settings\Administrator\My Documents\Innowera
    Terminal Server User license file not found or User ID not matched.
    Can anybody guide me please.
    Thanks.

    Hi,
    According to the error message, please use performance monitor to diagnose if it is a memory-related bottleneck and you can use the counters of the memory part in the article below:
    https://technet.microsoft.com/en-us/magazine/2008.08.pulse.aspx
    In addition, it may be due to thousands of open connections to the server are in a TIME_WAIT state. You can run "netstat -an" command on the affected server and client. If you see mutiple connections in the TIME_WAIT state, you can follow the article
    to increase the number of TCP/IP connections:
    https://msdn.microsoft.com/en-us/library/ee377084(v=bts.70).aspx
    Furthermore, if you are running windows server 2003, please make sure that you have installed the KB 948496 and stop all services that you don't need.
    Best regards,
    Susie
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • Deploy JDBC driver for SQL server 2005 on PI 7.1

    How to deploy JDBC driver for SQL server 2005 on PI 7.1
    We are in SAP NetWeaver 7.1 Oracle 10G
    Third party system is  SQL server 2005
    There are different JDBC versions are available to download for SQL server 2005.
    I am not sure about the applicable version for the PI 7.1 SP level. Again JMS Adapter needs to be deploy along with this.
    Please help

    Hi,
    Hope this How to Guide help you.
    How To Install and Configure External Drivers for the JDBC & JMS Adapters from
    www.sdn.sap.com/irj/sdn/howtoguides
    Regards,
    Karthick.
    Edited by: Karthick Srinivasan on Apr 13, 2009 4:07 PM

  • Deploying JDBC driver for SQL Server 2005 on PI 7.1

    How to Deploy JDBC driver for SQL Server 2005 on PI 7.1 on Windows 2003 server
    We are in NW PI 7.1 and third party db is sql server 05.
    Found How-to Guide SAP NetWeaver u201804 but unable to find for NW PI 7.1
    Can any one help me on this? (looking for guide step by step procedure)
    Regards
    Mahesh

    Hi,
    Check these:
    Re: Installing JDBC Drivers for PI 7.1
    how to deploy MS Sql Server 2005 and 2008 jdbc driver
    Mention of a SAP Note in the first link or refer this note [831162|https://service.sap.com/sap/support/notes/831162]
    Regards,
    Abhishek.

  • Error deploying JDBC driver for SQL Server 2005

    Hi all
    I'm trying to deploy a JDBC driver for MS SQL Server 2005 (downloaded [here|http://www.microsoft.com/downloads/details.aspx?familyid=C47053EB-3B64-4794-950D-81E1EC91C1BA&displaylang=en]). When I try to deploy it according to the instructions found [here|http://help.sap.com/saphelp_nwce10/helpdata/en/51/735d4217139041e10000000a1550b0/frameset.htm] it fails.
    The error in the logs doesn't give any useful information though. It only says Error occurred while deploying component ".\temp\dbpool\MSSQL2005.sda".
    Has anyone else deployed a driver for SQL Server 2005, or perhaps have any suggestions of what else I could try?
    Thanks
    Stuart

    Hi Vladimir
    That's excellent news! Thanks for the effort you've put into this. I'm very impressed with how seriously these issues are dealt with, specifically within the Java EE aspects of SAP.
    May I make two suggestions on this topic:
    1. Given that NWA has such granular security permissions, please could the security error be shown when it is raised? This would help immediately identify that the problem isn't actually a product error, but rather a missing security permission (and thus save us time and reduce your support calls).
    2. Please could the role permissions be clearly documented (perhaps they already are, and I just couldn't find the docs?) so we know what is and isn't included in the role. The name is very misleading, as a "superadmin" is generally understood to have no limitation on their rights - so clear documentation on what is in-/excluded would be most helpful.
    On a related topic, I came across another issue like this that may warrant your attention (while you're already looking into NWA security issues). I logged a support query about it (ref: 0120025231 0000753421 2008) in case you can retrieve details there (screenshots, logs, etc.). It's basically a similar security constraint when trying to create a Destination. I'm not sure if this is something you would like to include as standard permissions within the NWA_SUPERADMIN role or not, but I think it's worth consideration.
    Thanks again for your help!
    Cheers
    Stuart

  • Adobe Illustrator in out Terminal Server environment. How is the licensing work for Terminal Server installations?

    Adobe Illustrator in out Terminal Server environment. How is the licensing work for Terminal Server installations?

    You can find all forums here:
    https://forums.adobe.com/welcome

  • Configuring HWIC-8A card for terminal server access

    Hi Friends,
    I have a 3825 router having HWIC-8A async card, and want to cnfigure that for terminal server connectivity. I believe it will have different config to NM-16A module config. any advice please.
    Thanks..
    Arun

    Having them both kills being able to access the Net.Take out the gateway on your loopback adapter and network traffic should happen as normal :)
    Is this configured only in TNSNAMES.ORA, and if so how?It's configured in listener.ora, but changing the port won't change the amount of traffic nor the Oracle load, it will just make everything slightly more confusing to everyone trying to help you troubleshoot your machine ;)
    ~Jer

  • Group Policy For 2008 Terminal Server Users Default Open With Not Working

    I'm trying to change the default open with behavior for jpg files on my terminal server. I created a Group Policy that changed it to MS Paint to Office 2010 Picture Manager. The policy appears to apply correctly but jpg files still open in
    Paint. When a user is logged on, if they look at the properties of a jpg, it shows Photo Gallery as the program to open it but when opened, it opens in Paint.
    Has anyone seen this behavior before?
    Orange County District Attorney

    > did. It would be helpful to know where the changes actually go in the
    > registry to see if they did or now.
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • Windows 2008 Terminal Server "user must change password at next logon" problem with Windows 7 client.

    Hi,
    I have a fully patched Windows 2008 SP2 Terminal Server and a fully patched Windows 7 client.
    I have logged into the Windows 2008 SP2 Terminal Server server with a test account via RDC before.
    When I try to log in via RDC to the 2008 TS with a test account which has been marked with the setting "User must change password at next logon" I get the RDC message "You must change your password before logging on the first time.  For assistance, contact your system administrator or technical support."  I need to force the user to change their password once it has been issued, any ideas on how this can be done?
    Thanks,
    Dan

    This does not resolve my issue all the way. I'm having the same problem; When i'm "deploying" users, i always want the users to set their own passwords. Ok, so I then set the auth mode to "RDP Security layer". It seemed to work fine, and it does for that
    special purpose.
    Just like Daniel, my clients are connecting to our terminal server from several/different "customer-domains" So, they can't logon locally(on their local computer) and change their password, it has to be done THROUGH the terminal server.
    But if I turn on RDP Security Layer, users can't use remoteapp through tsgw they only get: "Your Remote Desktop Connection Failed because the remote computer cannot be authenticated" Any ideas?
    Also, our terminal servers is round robin based in a farm. So users connect to: tsfarm.domain.com(yes, public a-record which resolves to two internal adresses) This is because, we're using a wilcard *.domain.com as SSL certificate.
    But, when i'm using this, our clients sometimes get double auth when they login. I only get the double auth when tsfarm.domain.com resolves to server A, but the session broker wants the user to be on server B.(load balancing)
    This does not occur when SSL is enforced, any ideas?

  • Can't copy past to desktop on Terminal server user profile

    Hi,I have a problem that I've seen posted in the forums but can not find a solution.  I am using windows 2008 r2 Terminal servers to log user on to the environment.  My users can't create/Copy/save files/shortcuts to the desktop.  My Terminal
    server profile path is filled out correctly and each user has full access to respective profile folder.
    Any help would be very much appreciated. 
    Thank you. 

    Hi,
    Thank you for posting in Windows Server Forum.
    Which client RDP version using for your environment?
    Please make sure that you not enabled “Do not allow clipboard redirection” in GPO setting under below mention path.
    Computer Configuration\Policies\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Device and Resource Redirection
    User Configuration\Policies\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Device and Resource Redirection
    More information.
    Make Local Devices and Resources Available in a Remote Session
    http://technet.microsoft.com/en-us/library/cc770631.aspx
    Also see that you have enable clipboard redirection. On client side please check following setting:
    1.  On Windows client machine, type mstsc.exe and press Enter.
    2.  Click the Options button, click Local Resources tab and make sure that the
    Clipboard check box has been selected.
    Hope it helps!
    Thanks.
    Dharmesh Solanki

Maybe you are looking for