Hi I have a Windows 2000 Domain with a terminal server as a member server. I have a OU setup so that certain users (when connecting off site to the terminal server) have restricted access, like not being able to shut down the server for example. This OU has a Group Policy on it and everything is worken fine. Now as time goes on I am implementing more windows xp boxes on site. (windows 98 was used primarily and GP's did not affect it)
Now lets say I have a user in the OU for restricted access when he comes in on the terminal server. Now when this user logs on "on site" (windows xp) his computer is locked down, just like it would be if he were to log on the terminal server from home. Is there anyway to seperate or over-ride the AD settings when he logs on from a computer on site. He needs restricted access when off-site but no restriction when on-site. Most, if not all settings in the GPO are under user configuration, just a FYI.
Now lets say I have a user in the OU for restricted access when he comes in on the terminal server. Now when this user logs on "on site" (windows xp) his computer is locked down, just like it would be if he were to log on the terminal server from home. Is there anyway to seperate or over-ride the AD settings when he logs on from a computer on site. He needs restricted access when off-site but no restriction when on-site. Most, if not all settings in the GPO are under user configuration, just a FYI.