beancole Posted September 10, 2014 Posted September 10, 2014 Seem to be on here a lot recently but here goes. Previous IT manger set up remote gateway. Personally I think the system is pointless, all staff can download office for £8.95 or use a school laptop and no other software can run on it (single geographic licence) so like I say pointless, documents they can access from home access plus. But the head is adamant we keep it. Problem is as follows. It worked fine until I scraped the entire group policy and rebuilt every machine in the school. Users can still log in to the remote gateway but now they get a start menu (where I have no idea where it comes from???) and they don't have access to documents or shares. Staff can create their own share and save it to the desktop as a short cut but that's not a proper solution. if I click on the image icon on the start menu I get this error message - The operation has been cancelled due to restrictions in effect on this computer. Please contact your system administrator. So this is clearly something in my users group policy that is breaking it down. I have very few GPOs actually set and they are all there for a reason. I need a way of adding the shares to the start menu or desktops. Anyone got any ideas?
Quackers Posted September 10, 2014 Posted September 10, 2014 It might be in loopback mode with it being a terminal server so it can be locked down a bit more with the machine being accessible remotely. So look at where the computer account is in Active Directory and see if its in loopback mode (its a computer policy setting). 1
beancole Posted September 11, 2014 Author Posted September 11, 2014 It might be in loopback mode with it being a terminal server so it can be locked down a bit more with the machine being accessible remotely. So look at where the computer account is in Active Directory and see if its in loopback mode (its a computer policy setting). There is a GPO called TS_Loopback. Is this something standard? However I don't think this should be the issue, The system used to work before and the only changes made are the ones in my group policy. The server is not in the OU of any of my computer policies so these can't effect it. The users have policies set within their Usernames OU. This is what I have created. I think the issue may be something to do with the Start menu options in the GPO. I turned off libraries for one but 'Computer' should still be an option.
beancole Posted September 11, 2014 Author Posted September 11, 2014 Further to that upon looking through the TS_Loopback policy I found this setting User Group Policy loopback processing mode is Enabled and set to Merge. I dont understand what Microsoft are trying to explain in the description.
beancole Posted September 11, 2014 Author Posted September 11, 2014 Without Changing anything only opening the group policy in a windows 8 machine. Now any users that log into the remote desktop all the applied GPOs for the remote desktop are then applied to computers they log into (even though they are ion different OUs). From what I can see this is something to do with this loopback thing. Anyone out there know what I need to do?????? Im worried these policoies are going to start replicating accross the network.
Achandler Posted September 11, 2014 Posted September 11, 2014 The policy isn't standard No. It has been named liek that by a predecessor. This User Group Policy loopback processing mode is Enabled and set to Merge means that User policies set, I.e the polciies you have set for each individual user, probably at OU level within the students and staff parts of your setup, will get merged into any policies that are set on the Terminal Server, it is a way to force User Policies onto a person logging into a specific computer (or terminal server in your case). From what you have said you will need this enabled, so that your staff and students are locked down appropiately. 1
beancole Posted September 11, 2014 Author Posted September 11, 2014 The problem is that policies set by my predecessor appear to be working their way now into my normal group policy accross the network and not just limited to the terminal services server. How do I stop it from going both ways?
beancole Posted September 11, 2014 Author Posted September 11, 2014 When I check the RSOP data on an individual machine it doesnt appear to show anything set in the TS_Loopback but I can see that setting are being applied
Achandler Posted September 11, 2014 Posted September 11, 2014 That policy would only have affect on anything within the OU which it is applied, so check where TS_Loopback policy is applied. The TS_Loopback is merely making User Setting from the User's OU apply, so if you have a user setting that changes the background normally, and it is set on an inidividuals OU, then this setting would also apply to the Terminal Server, because the loopback applies user settings. 1
beancole Posted September 11, 2014 Author Posted September 11, 2014 I don't get what has happened to my test staff user. Its within a separate OU which is blocked from inheriting. but now even when I log onto a freshly re-imaged computer again in a separate OU (again blocked from inheriting) the group policy is clearly messed up things like the start menu redirect to the right place but some things are restricted. I think it may be that the group policy hasn't replicated accross my DC's and im just catching the back end of a messed up policy. I hope to god thats the cae anyway.
Achandler Posted September 11, 2014 Posted September 11, 2014 That sounds highly inplausible i'm afraid. Group policy updates are virtually instant. Does your test user maybe have a profile setup that contains a start menu amongst other things. Also so there is no group policies applying to either the User OU or the Computer OU? 1
beancole Posted September 11, 2014 Author Posted September 11, 2014 My User OU has a policy and my Computer OU has a policy. Both are in no way linked to the TS_loopback policy or the OU in which it's contained. I have changed everything that I changed in the TS_Loopback policy back to original bar 1 thing so process of elimination dictates it must be this. Set Path for Remote Desktop Services Roaming User Profile I set this to our new server profile location I'm going to set it back and hope for the best but I dont understand how this can effect when we log into other computers in other OUs there must be something in the profile that is breaking the start menu (making it loose documents, devices and printers etc.)
Achandler Posted September 11, 2014 Posted September 11, 2014 In your users do you set a remote desktop services profile path? There should be a tab for it within Active Directory, mayeb this is pointing to a different profile then your original and as such is causing you the issues. 1
beancole Posted September 11, 2014 Author Posted September 11, 2014 the remote desktop Profile Path is blank in my test user.
Achandler Posted September 11, 2014 Posted September 11, 2014 It makes it very difficult to establish what is happening then, without actually seeing it. From what you are syaign basically, no matter what computer you login you are getting extra policies applying that shouldnt be. On your RSOP you said the policy is applying but blank. On your test user in your new OU, you should only have 2 policies applying if you have blocked inheritence on everything, is that much at least true? Or is there more policies then expected appearing?
beancole Posted September 11, 2014 Author Posted September 11, 2014 (edited) I'll consolidate;- all my computers are in a Workstations OU with a computers policy (no inherit) all my users are in a Usernames OU with a users policy (no Inherit) I have a terminal server gateway in another OU with a policy called TS_Loopback (where loopback is enabled) I have a user called stafftest in the Usernames OU. This user logs into the remote gateway fine. I can see that it is also applying the usernames GPO as the users homepage is set correctly. When the user now logs into the network on a computer in the workstations OU the workstations policy is applied. I can see this when I collect the RSOP data that this policy and only this policy is applied. However if I click on the start-menu and click the image in the top right I get the same restrictions that are set on the remote desktop are also set here. (This operation has been cancelled due to restrictions in effect on this computer) (Also on a slight side not but its probably pertinent. If I log into the remote gateway with stafftest, then at the same time log into a network computer with stafftest then I also get the Remote desktop startmenu that is set by the TS_Loopback policy.) The only thing that links anything here is the user profile, that could explain possibly problems with the look of the start menu but not the 'restrictions in effect on this computer' I have also managed to replicate this with a copy of stafftest, stafftest2 same OU etc. The problem arises when a user is logged into the remote gateway then also logs into the network. It appears to be destroying the profile and somehow copies accross the restrictions. Edited September 11, 2014 by bencole
Achandler Posted September 11, 2014 Posted September 11, 2014 Ok, so within the workstations computer policy does it have loopback enabled as well, or is it purely computer settings? People setup things differently. When a user logs into a workstation in your network two things happen, both the Computers Policy and the Users policy applies. When a user logs into the terminal server then the following two things happen the TS_Loopback Policy and the Users Policy (because of loopback) So there are a couple of things that are common, mainly the User Policy, the User Profile. The problem must be within there. 1
beancole Posted September 12, 2014 Author Posted September 12, 2014 There is no Loopback on my normal group policy on workstations and users so this problem is entirely with profiles. (took me a while to stop flapping like a tap dancers fanny and get my head straight.) So the problem is entirely with the users policy. This is a separate issue to my original one and one created by myself trying to test in house. So if you log into remote desktop then also into a school computer it kills your profile. Basically never been a problem as staff cant log in from home and come into school and log in. (It times out at home after inactivity) However in trying to fix this problem I have learnt more about the group policy related to Remote desktop so should be able to fix my initial issue of not having any user documents and shares. Now to fix I think the simplest way is to add the 'Computer' icon to the desktops of users. Google time, unless anyone knows?
Achandler Posted September 12, 2014 Posted September 12, 2014 It is here: User Configuration -> Policies -> Administrative Templates -> Desktop -> Remove Computer icon on the desktop 1
beancole Posted September 15, 2014 Author Posted September 15, 2014 Just had a member of staff come in who was on remote desktop over the weekend and now their user is knakkard. They weren't logged in in both school and remote desktop so it cant be the problem I thought. Unless anyone has a better idea I'm removing remote desktop.
beancole Posted September 15, 2014 Author Posted September 15, 2014 Might very well have to blog this one. Found the problem was within the profile. The issue was the remote desktop is killing the theme when you log back into the network. Simple fix just open control panel, personalisation, and select the windows 7 aero theme. Now just to set this a standard via GPO and hopefully the issue should not again arise.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now