Jump to content

Recommended Posts

Posted

I'm currently battling with our Citrix group policies, trying to get staff and students to go out over separate proxies.

 

At the moment, staff and students use separate proxies when on normal desktops; staff get unfiltered and students get restricted. However this stops being the case when they logon to a Citrix thin client. Instead, everyone ends up going out over the same proxy.

 

Now, staff and students are under separate OU's in Active Directory ('Staff Users' and 'Student Users') and they have separate GPO's applied to them ('Staff IE Policy' and 'Student IE Policy'). As mentioned this works fine on normal desktops no problem.

 

When staff login to Citrix however, they get no proxy settings at all. In order to give them proxy settings, I created two new GPO's under the 'Citrix Servers' OU ('Staff Citrix IE Policy' and 'Student Citrix IE Policy') each with the relevant proxy settings. Now when staff or students login to Citrix, everyone gets the same proxy (depending on what 'Security Filtering' settings I use).

 

With regards to the security filtering, I have tried adding and removing various groups to try and get this to work. Here's what I've done:

 

Removed 'Authenticated Users' group from both GPO's. Added 'All Students' group to the students GPO and 'All Staff' group to the staff GPO.

This resulted in no proxy settings being applied.

 

Add 'Authenticated Users' to one of the GPO's and everyone gets that proxy setting regardless of link order.

 

Add 'Authenticated Users' to both of the GPO's and everyone gets whichever is highest in the link order.

 

'Enforcing' one or both of the policies makes no difference.

 

Am I missing something simple with the security filtering? It was my understanding that a GPO will only apply it's setting to whichever group/user/computer is in the security filtering area?

 

Yet it appears that no matter what groups or users I put in the security filtering area, the policy will not get applied unless the 'Authenticated Users' group is there; and if that group is there then that policy gets applied to everyone regardless of what else is in there.

 

We are using XenApp 6 installed on Windows Server 2008 R2 with IE 9 as the browser.

 

Any help would be much appreciated.

Posted (edited)

Have you looked to see if there is a GPO applying at the server level that is taking priority?

 

Edit: It would be worth running resultant set of policy to see if anything unexpected is applying.

Edited by foofighterjim
Posted

Hi foofighterjim, thanks for your quick response.

 

As far as I'm aware these two GPO's are being applied at the server level.

 

Sorry should have mentioned, I have run RSOP and gpresult as both staff and student. Both of these show that:

 

When both GPO's have 'Authenticated Users' in the security filter, the one highest in link order gets applied. When only one has 'Authenticated Users', that one gets applied. When neither have 'Authenticated Users' the default domain policy gets applied.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...