Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Wanet Telecoms Ltd on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Policies problem: citrix users and citrix administrator

Status
Not open for further replies.

isterios

IS-IT--Management
Apr 16, 2003
205
NL
The problem is quite complex:

We have a domain with global policies applied on users.
I have to apply my own policies for Citrix, for these same users. So these users connect sometimes on the domain (without Citrix) and sometimes on Citrix.

I cannot create a Citrix OU (group) on the active directory: as a matter of fact, if I create a citrix OU on the domain with my citrix policies, there will be a conflict between the domain policies and the citrix policies (my citrix policies are much more stronger than the domain policies). Ex: hide drives. If I hid drives on this OU, the users won't see anymore their drives when they connect on the domain (without Citrix), which is not possible.

I cannot create a Citrix OU with specific accounts on the active directory, only for Citrix: I would have for each account to reconnect the mail, the drives mappings etc.

If I apply policies on the citrix server, locally, the policies apply on my administrator account also (like no registry access, no start group access, no drives mapping access etc.) And I can not anymore administrate my server.

I would like a kind of local OU (not domain OU) with policies that don't apply on the administrator account.
But it seems local policies on local group is impossible.

I must specify that I have no permissions to modify the domain policies (but I could obtain permissions to manage a Citrix OU on the domain).



What could I do acording to you?

Thank you.



 
best way to do this is indeed create a Citrix OU.
Place your citrix servers in this OU
Apply a computer based policy to set Computer related lockdown. (for instance the Group Policy Loopback mode should be replace)
Next create a user lockdown policy.. For the admins set a "deny apply policy" security setting..
Admins won´t be affected by the policy then..

Hope this helps a bit....




Petje
A+, MCP, MCSE on NT4.0 and windows 2000 and Windows server 2003 and CCEA
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top