DLU Policy for terminal server

Hi all
I am trying to apply a DLU policy to allow users to remotely login to a terminal server. However, I do not want the DLU policy to allow users to have remote desktop access to other workstations.
Right now I have 3 DLU policies configured
DLU Admin - Grants IT users full admin access to all devices
DLU Users - Gives employees access only to the users and power users group on the managed devices
DLU Remote - grants remote desktop access to specific users
Is there a better way to assign a remote dlu policy to a specific device?
I want to lock down the DLU to specific devices.
thanls

JSorrenti,
It appears that in the past few days you have not received a response to your
posting. That concerns us, and has triggered this automated reply.
Has your problem been resolved? If not, you might try one of the following options:
- Visit http://support.novell.com and search the knowledgebase and/or check all
the other self support options and support programs available.
- You could also try posting your message again. Make sure it is posted in the
correct newsgroup. (http://forums.novell.com)
Be sure to read the forum FAQ about what to expect in the way of responses:
http://forums.novell.com/faq.php
If this is a reply to a duplicate posting, please ignore and accept our apologies
and rest assured we will issue a stern reprimand to our posting bot.
Good luck!
Your Novell Product Support Forums Team
http://forums.novell.com/

Similar Messages

  • Group Policy design for Terminal Server

    Hi, I am mixed about group policy design for Terminal server
    My Infrastructure is so;
    Zone
          ->Department
                       ->User
                       ->Computers
          ->Department
                       ->User
                       ->Computers
          ->Department
                       ->User
                       ->Computers
    Server
           ->OtherServer
            ->TerminalServer (TerminalComputersGPO)
    I create two group policy for user and for terminal server computers (security filtered for Terminal_Users)
    I want to use terminal server user policy but it must effect
    just in terminal computers. not TS user's computers. what i must do? where i must locate it?
    Please click "Vote As Helpful" if it is helpful for you and "Propose as Answer"

    Hi Davut EREN - TAT,
    According to your description, you would like
    terminal server user policy applying to users which log on to terminal computers. Right?
    As MuhammadUmar's suggestion, you can use Loopback in replace mode. The GPO list for the user is replaced in its entirety by the GPO list that is already obtained for the computer at computer startup.
    In the real work environment Loopback processing of Group Policy is usually used on Terminal Servers. For example we have users with enabled folder redirection settings, but we do not want these folder redirection to work when the users log on to the
    Terminal Server, in this case we enable Loopback processing of Group s Computer account and do not enable the folder redirection settings.
    For more information about this policy, please refer to the following articles:
    Loopback processing with merge or replace
    Loopback processing of Group Policy
    Regards,
    Lany Zhang

  • Adobe Illustrator in out Terminal Server environment. How is the licensing work for Terminal Server installations?

    Adobe Illustrator in out Terminal Server environment. How is the licensing work for Terminal Server installations?

    You can find all forums here:
    https://forums.adobe.com/welcome

  • Outlook is running to slow for terminal server users

    All tried but no luck .thanks

    Outlook is running to slow for terminal server users and very slow updating inbox. Can anyone suggest how can i increase speed for the users ?
    Office 2013
    exchange 2010
    This topic first appeared in the Spiceworks Community

  • Configuring HWIC-8A card for terminal server access

    Hi Friends,
    I have a 3825 router having HWIC-8A async card, and want to cnfigure that for terminal server connectivity. I believe it will have different config to NM-16A module config. any advice please.
    Thanks..
    Arun

    Having them both kills being able to access the Net.Take out the gateway on your loopback adapter and network traffic should happen as normal :)
    Is this configured only in TNSNAMES.ORA, and if so how?It's configured in listener.ora, but changing the port won't change the amount of traffic nor the Oracle load, it will just make everything slightly more confusing to everyone trying to help you troubleshoot your machine ;)
    ~Jer

  • Sequencing for terminal server

    Hi,
    Is there any prereq we should take into account when creating an app for terminal server (Windows 2008 R2)?
    The problem we are facing now is that App-v packages are working correctly for 1 user but others (on the same terminal server) don't see the shortcut. If we copy past the screenshot to their menu it works fine.
    Please advise.
    J.
    Jan Hoedt

    I suppose it's SP1 for SCCM 2012, as this adds App-V 5 support.
    Do you target machines or users in your deployment type? 
    Do you do any 'bad tricks' with the start menu (like redirecting it)?
    Falko
    Twitter
    @kirk_tn   |   Blog
    kirxblog   |   Web
    kirx.org   |   Fireside
    appvbook.com

  • Cable type for terminal server

    please has anyone tried to connect using cisco 2811 router with HWIC-8A/S-RS232 as terminal server to an alcatel router.
    please can i know correct cable specification to achieve this purpose and a similar config that has been used before.
    thanks in advance for help.

    Product Name :- High Density 8 Port EIA-232 ASYNC Cable Spare
    Cable Length    10 ft
    Product Type    Data Transfer Cable
    Compatibility  
        * Cisco Module HWIC-8A/S
        * Cisco Module HWIC-16A
    Conductor    Copper
    PRODUCT DESCRIPTION    HIGH DENSITY 8PORT EIA-232 ASYNC CABLE SPARE
    TYPE    SERIAL RS-232 CABLE

  • Firefox lockdown for Terminal Server ?

    I search a lockdown (GPO or mozilla.cfg) for Firefox 8 to install on Terminal Server?

    Hi,
    I have similar problems with AddOns on Windows Terminal Server 2008.
    In the first place I installed für Each Termnial User separatley as suggested above. This must be wrong because the AddOns only worked for the user for wich the AddOns where installed latest and didn't work for all other users.
    So the next time I uninstalled the AddOns for all Terminal Users and Installed again with local administrator account in install mode and started SBO in Admin Mode for that procedere. Now all users get the error message "A new version of xxx was installed. Please upgrade the AddOn in the common DB" and the AddOn Manager showing a different Version Number than the AddOn Administrator.
    I didn't found anything in Documentation Ressource Center nor in the SBO Notes.
    Has somebody a definite Installation procedure for Client with AddOns on Windows Terminal Server 2008?
    Thanks
    Christian Birkholtz

  • Adding another exchange account Outlook 2013 Pro Plus for terminal Server users

    Really hoping someone can offer some advice on this one as I have wasted far to many cycles trying to figure this out.
     Company I work for recent purchased another company and we are in the process of bringing them into our network.  They currently run a a 2008 R2 terminal server where all users connect to for there day to day work.  A number of applications
    are installed including Office 2013.
    All users have Outlook 2013 configured to access their exchange server for email and this works fine.
    The first step in bringing them into our fold is to add an email account for Our Exchange  server without removing their existing exchange configuration or Outlook Profile.  So the one profile will have both exchange accounts listed and they can
    continue to get email from their server but as well email from our domain.
    I created a MSP file and tested pushing this out using PDQ Deploy to a few workstations here in our office and it works fine.  I then started to work on deploying in their environment.  PDQ Deploy will not work as they are all terminal Services
    Clients.  So I tried to push out via GPO.  I created the GPO Initially wanting to use a package and apply that GPO to an AD group.  However it will not let me deploy a MST as a package.  So I then tried moving it to a script that would
    run at logon.  That too is not working.
    I know I could enter install mode then run the MSIEXEC.EXE \config.MSP but that takes away the ability to control the role out.
    Any other ideas on how to get this done.

    Using the MSPfile method would require the logged-on user to have the necessary Windows permissions to run setup.exe, and on an RDS/TS Session Host, that's not likely to be available. (since it's not a great idea to give end-users those permissions on a
    shared system like RDS/TS)
    But you might be able to do it with a PRF file and an Outlook launch command, like this?
    http://technet.microsoft.com/en-us/library/cc179062(v=office.15).aspx
    Don
    (Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
    This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

  • Embedded Menu Manager for Terminal Server

    Has anyone use EMM as a nice friendly interface for their terminal server (ie router with NM-16A and octal cables)?
    when I ask the framework to run the following command it gets stuck will a blinking cursor and clear screen
                <IOSExecCommand>"connect 10.1.1.1 2000"</IOSExecCommand>
    however removing the port number allows it to connect fine.
                <IOSExecCommand>"connect 10.1.1.1"</IOSExecCommand>
    same symptom if iI were to replace connect with telnet
                <IOSExecCommand>"telnet 10.1.1.1 2000"</IOSExecCommand>
    even setting up an iphost does the same ie:
                   ip host R1 2000 10.1.1.1
                <IOSExecCommand>"connect R1"</IOSExecCommand>
    All of these commands work fine from the # prompt

    I'm suprised any of these work as they are all interactive commands.  You must be running an earlier version of IOS.  You can only run EXEC commands that will return you to a prompt without user intervention.  Using EMM as a terminal server menu is not going to work.  However, what you could do is have a classic IOS menu call the emm command when one option is selected.  That could take you to a guided menu that allows one to perform additional commands other than connect to device consoles.

  • Jabber for terminal server support

    Are there any work around's to allow jabber to work in a terminal server environment? I have a client that needs this functionaily and cannot upgrade to XenDesktop.
    Please help.

    Hello,
    Regarding BFCP and content sharing from Cisco Jabber Video for TelePresence 4.8.6 on Windows to Jabber Video 9.3.9 for iPad clients.Jabber Video for TelePresence(Movi) cannot stop sharing presentation on the call.
    I wish to know if what versions this is actually fixed in? I have read the release notes and I am still unable to find an answer.
    I read in Cisco Bug Toolkit this is a known bug CSCup04761 and the only workaround is to disconnect the call.
    CSCup04761 - Movi can't stop sharing main video presentation Symptom:Jabber Video for TelePresence(Movi) cannot stop sharing presentation on the call.
    Conditions:When using Movi to share a presentation to an endpoint that doesn't support BFCP (such as Jabber for iPad).
    Workaround: Disconnect the call.
    Details Last Modified: Oct 9,2014
    Status:Fixed
    Regards
    Nicholas

  • How To Disable DLU Policy For A Group Of Users

    We are running Zenworks 7.x on Novell netware 6.5 sp8. I have my User package existing within the Context where the user accounts exist. Also the User Package is associated to that user Context. I have a need to deny a specific group of users access to the DLU Policy of the User Package. However I will need the users to have access to all other Policy packages withing the same User Package (ie, iprint policy, remote control policy, etc).
    Is it possible to deny a group of users access to the DLU policy but not the other Policies within the Associated user package?

    Originally Posted by wanman
    We are running Zenworks 7.x on Novell netware 6.5 sp8. I have my User package existing within the Context where the user accounts exist. Also the User Package is associated to that user Context. I have a need to deny a specific group of users access to the DLU Policy of the User Package. However I will need the users to have access to all other Policy packages withing the same User Package (ie, iprint policy, remote control policy, etc).
    Is it possible to deny a group of users access to the DLU policy but not the other Policies within the Associated user package?
    Take a copy of your existing User package, disable DLU in this new package and assign it to these specific users that you don't want DLU to apply.
    Thomas

  • Deploy an MSI for Terminal server users

    Hello,
    I have faced with the issue which I can't resolve on my own - the MSI is not run when the user logs on. Moreover, I don't see the GPO applied in the Group Policy Results for the user:
    Here is what I did on the server side:
    1. Created a separate OU for testing (actually, it doesn't work if I apply a policy at the domain level).
    2. Created a test user account.
    3. Created a shared folder (Read for everyone). Made sure that an user can read files from that folder.
    4. Placed the msi file in the shared folder. Before doing that, I tested the installer in the fields running the "msiexec.exe /i /s" command.
    5. Created a new Group Policy object where I added a new software installation at the User Configuration node. I specified the filepath in the following format -
    \\server\folder\msifile . Assigned. Chose the
    Install this application at logon. Maximum (User Interface).
    6. Linked the GPO to the OU where the user resides.
    7. The Settings in the GPO apply only for the specified user. Also I checked permissions on the Delegation tab for the user - Read / Apply Group Policy are selected.
    Here is how it looks like:
    Most probably I tried to adjust some properties for troubleshooting. But nothing helped.
    When I logon as a domain user I see that the GPO was applied successfully (gpresult.exe confirms). But I don't see any installation wizard, nor MSI installed. The result is shown on the first screenshot.
    I even don't get any errors in the Group Policy log. I have a feeling that user settings in my GPO are ignored by the system. Why does it happen? Is there any setting I missed setting up a new GPO?
    P.S. I have tried turning on various Group Policy settings located in the Administrative Templates / System / Group Policy.

    Hi Eugene,
    Based on your description, to make sure that this is not caused by fast logon optimization feature, we can enable the following setting:
    Computer Configuration\Administrative Templates\System\Logon\ Always wait for the network at computer startup and logon
    After enabling this setting and updating the policy, we can try logging off and logging on again to see if it works.
    Regarding fast logon optimization, the following article can be referred to for more information.
    Description of the Windows Fast Logon Optimization feature
    http://support.microsoft.com/kb/305293/en-us
    Hope it helps.
    Best regards,
    Frank Shen

  • Installing terminal server role on windows server 2012 to use for Windows server 2008 R2 machines.

    Dear
    Our current setup is as follows :-
    Active Driectory is in Windows Server 2003.
    Citrix Xenapp version 5.6 with all Xenapp servers in Windows Server 2003
    Now we are upgrading our Citrix farm to 6.5 and all Xen app servers into Windows Server 2008R2.
    We did the configuration and testing; everything works fine except the terminal server is not configured which gives the pop always for the expiry date.
    We do have license for 2012 terminal server which is not possible to downgrade for some reason and managent need to install new Windows Server 2012 for terminal server and activte the licenses.
    My question is :-
    1 Whether Windows Server 2008 R2 will get RDS cal license from Windows Server 2012 terminal server (RDS CAL license is of windows server 2012).
    2. What is the role and features I need to activate in Server 2012 in order to use for Citrix 6.5 (only applicable fetaure for getting the RDS cal license.) 
    3. Whether I can add this 2012 server into domain. Is it possible to add 2012 server into Windows Server 2003 AD. 
    Your early reply is highly appreciated.

    Thanks Jeremy..
    I got exactly the right answers I am lookoing for ..
    I successfully activated the terminal service on the newly created Windows 2012 Server and installed the retail license pack we had of 50+50+25 keys . It later shows the 125 keys successfully applied.
    when I tried to link the Xenapp (Windows Server2008R2) to the license server, it first gives me error that session host service role is not installed on the ternial server. So I installed that role also in the terminal server.
    But now its anothee error as below.
    RDS Cals are not available for this Remote Desktop Session host server, and licensing Diagnostic has identified licensing problems for the RD session host server.
    1. Is it wrong I did by installing session host server role into the terminal server (but really it gave me error like 'session host server role is not running on the license server' when I tried to link the license server).
    2. Is it the problem that Windows Server 2008 R2 will not get license from 2012 RDS CAL license.
    3. whether Clearing house will take time to update the license.
    Your reply is highly appreciated. I need to know whether any other way I can link the Windows Server  2008 R2 Servers (Xenapp) to the license server.

  • Application redraw issue over Citrix and Terminal Server

    Hi All,
    We provide a client-server application which connects to a SQL Server database. The middle-tier is hosted on an application server (Windows Server 2008 R2) which in turn connects to the SQL Server database. The fat client can either be installed on user laptops/desktops
    or published using Citix/Terminal services.
    We have a long standing issue which frankly I just cannot fathom. A customer has published the client via Citrix to users and using roaming profiles. If an employee is using the application in London, the roaming profile is created on a server in London and
    connects to the middle-tier in London. If an employee is using the application in Glasgow, the roaming profile is created in Edinburgh and the user connects to the middle-tier in London. The customer is also using DFS
    The roaming profile consists of the 'My Documents', 'My Pictures', 'My Videos', 'My Music' and 'Windows' folder. Distributed File System (DFS) is used for roaming profile folder replication between offices. See http://technet.microsoft.com/en-gb/library/cc732863%28v=ws.10%29.aspx
    The Edinburgh users are experiencing application redraw issue where the interface loads in chunks. For example, when a user scrolls up and down or left and right, the data loads immediately (from SQL Server) but the interface (GUI) loads in blocks. You can
    actually see each segment of the GUI components loading. The issue also occurs if connecting via a Terminal Server where the application is also installed.
    For London users, it all works fine. If an Edinburgh user comes to London, they have no issues.
    The network connection is super fast between the various offices.
    The application is built using C++ and Delphi and uses the GDI API to draw the objects.
    Any guidance is appreciated.

    Hello partner,
    Thanks for contacting Microsoft. This is Sophia who is going to help with this issue. From your description, I learnt that users from Edinburgh have application redraw issue. However, London users worked fine. Please let me know if I misunderstand your purpose.
    Based on the information, it seems that the issue located in the middle-tier in London. Could you try building a middle-tier in Edinburgh and then test how the issue goes?
    Besides, based on my experience and research, by default the allocation of the bandwidth is 70 percent for graphics data and 30 percent for virtual channel data, meaning when bandwidth usage is under pressure, graphics data is guaranteed to get 70 percent
    of the available bandwidth.  And we can tweak the settings a bit for some scenarios. To change the settings, we can set registry values. Please reference the information below.
    ===========================================================================================================================================
    Note: For these settings to take effect, the computer must be restarted.
    Following is the list of registry values that affect the bandwidth allocation behavior. These are all DWORD values under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermDD:
    ·         FlowControlDisable: When set to 1, this value disables the new flow control algorithm, making it essentially First-In-First-Out (FIFO) for all packet requests. This provides results similar to Windows Server
    2003. (The default for this value is 0).
    ·         FlowControlDisplayBandwidth / FlowControlChannelBandwidth: These two values together determine the bandwidth distribution between display and virtual channels. You can set these values in the range of 0–255.
    For example, setting FlowControlDisplayBandwidth = 100 and FlowControlChannelBandwidth = 100 creates an equal bandwidth distribution between video and VCs. The default is 70 for FlowControlDisplayBandwidth and 30 for FlowControlChannelBandwidth, thus making
    the default distribution equal to 70–30.
    ·         FlowControlChargePostCompression: If set to 1, this value bases the bandwidth allocation on post-compression bandwidth usage. The default for this value is 0, which means that the bandwidth distribution is applied
    on pre-compressed data.
    For more information about RDP Bandwidth, please reference the article below.
    ================================================
    Bandwidth Allocation for Terminal Server connections over RDP
    http://blogs.msdn.com/b/rds/archive/2007/04/09/bandwidth-allocation-for-terminal-server-connections-over-rdp.aspx
    Top 10 RDP Protocol Misconceptions – Part 1
    http://blogs.msdn.com/b/rds/archive/2009/03/03/top-10-rdp-protocol-misconceptions-part-1.aspx
    If you have any concerns about the action plan above, feel free to let me know.
    Best regards,
    Sophia Sun
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

Maybe you are looking for