FN-GM Posted December 6, 2007 Posted December 6, 2007 Hi I want to set a policy that comes under User Configuration but to apply per computer not per user. Is this possible? Z
djm968 Posted December 6, 2007 Posted December 6, 2007 You need to enable Loopback Policy Processing within the GPO. Sorry just read your post again! Loopback processing will apply the USER settings to all users that logon. to Not sure if this is what you need. The other option is to write a script to modify the HKLM Registry Keys at user logon.
Nij.UK Posted December 6, 2007 Posted December 6, 2007 can you not just apply the gpo to and ou full of computers and this will have the same effect? therefore any user that logs into a machine which has user settings configured as part of the GPO will apply
FN-GM Posted December 6, 2007 Author Posted December 6, 2007 can you not just apply the gpo to and ou full of computers and this will have the same effect? therefore any user that logs into a machine which has user settings configured as part of the GPO will apply Does that work?
mrforgetful Posted December 6, 2007 Posted December 6, 2007 No. User Config settings will ONLY apply to users in the OU that policy is applied to. Computer Config settings will ONLY aaply to computers in OU the policy is applied to. If you create a policy with Computer Config settings in and apply it to an OU that only has User Accounts in it, that policy will do nothing.
ChrisH Posted December 6, 2007 Posted December 6, 2007 You will need loopback policy processing but be warned now it doesnt always work perfectly in my experience.
mrforgetful Posted December 6, 2007 Posted December 6, 2007 Yeh unless you use Loopback....but I'd advise you stay away unless your eyes depend on it. Makes troubleshooting a nightmare
Halfmad Posted December 6, 2007 Posted December 6, 2007 Hi I want to set a policy that comes under User Configuration but to apply per computer not per user. Is this possible? Z What is it you're trying to do? chances are someones already found a way of doing it
FN-GM Posted December 6, 2007 Author Posted December 6, 2007 Well i have the adm files for ranger, and you can set a user so it can only connect to certain machines. I would like to use this but per computer not user. So for example user 1 can logon to the library control and use ranger but only connect to the library machines. But then user 1 can logon to the ICT room control and open ranger again and then control the ICT room computers only. How do i do loopback please?
ChrisH Posted December 7, 2007 Posted December 7, 2007 Patience grasshopper! Comp configuration > admin templates > System > Group Policy of the GPO you want to enable loopback.
link470 Posted December 7, 2007 Posted December 7, 2007 Be pepared for stuff to stop working What kind of stuff? I was just about to implement this.
FN-GM Posted December 7, 2007 Author Posted December 7, 2007 I would test the policies first, depends what you are doing. If its home pages it shouldn't cause any problems. Z
Jose Posted December 8, 2007 Posted December 8, 2007 I use loopback policies to help use vanilla clients on a CC3 network, as your using Ranger I'm guessing your trying to have users logon to these PCs without the usual restrictions applying to the user accounts. My advice would be to create three different GPOs, each with loopback enabled. The first one called "student user settings via loopback", second one called "teacher user settings via loopback" third called "ICT staff user settings via loopback". Then deny the all students security group read and apply rights to the teacher and ICT staff's policies.
FN-GM Posted December 8, 2007 Author Posted December 8, 2007 I use loopback policies to help use vanilla clients on a CC3 network, as your using Ranger I'm guessing your trying to have users logon to these PCs without the usual restrictions applying to the user accounts. My advice would be to create three different GPOs, each with loopback enabled. The first one called "student user settings via loopback", second one called "teacher user settings via loopback" third called "ICT staff user settings via loopback". Then deny the all students security group read and apply rights to the teacher and ICT staff's policies. We want it so who ever logs onto that computer will be only allowed to use certain machines with ranger. Z
FN-GM Posted December 10, 2007 Author Posted December 10, 2007 Just to let you know I implemented it today and it works perfectly. So now with Ranger/Netsupport, when a teacher logs into the control machine in the library they can only connect to the library computers. Plus with the other group policies the horrible student bar has gone. Thanks a lot for your help guys! Z
mrforgetful Posted December 11, 2007 Posted December 11, 2007 Yeh with AB Tutor you just give them that room layout and no other. Never used Ranger.
deneb829 Posted April 30, 2012 Posted April 30, 2012 (edited) OK, I know this thread is a few years old, but I wanted to add a loopback story. I don't remember why we set loopback for our student OU (Server 2008) but somewhere along the line we forgot that it was done. Students logging on have no access to the control panel, can't right click on the desktop, and can't adjust other settings. Well, with loopback enabled, everyone, including administrators, who logged onto a workstation in this OU had these settings applied. It was making us nuts as it took us a bit to figure out why it was doing that. Once we disabled loopback, the restrictions were once again just applied to the student accounts in the OU. Wow, this thread was started on my son's 1st birthday, and now he's halfway through Pre-K. Windows issues are just so ... timeless! Edited April 30, 2012 by deneb829
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now