Oh, and a PS. Although I'm still working on it, MS says to apply a GPO Loopback policy to the terminal server, which is *supposed* to give you the ability to set a GPO that will only be effective when a user logs into the terminal server. This should, in effect, allow me to setup a GPO that will apply only to the users when they logon to my terminal server. I'm gleaning this from KB 260370, but again, I haven't tested it yet.
Thanks.