none
GPO to log off idle terminal server sessions excluding 1 of the terminal servers

คำตอบ

  • Hi,

    Thanks for your posting.

    We can configure Computer Configuration Group Policy for Terminal Services in Windows Server 2008. The following Group Policy nodes are available under the Computer Configuration\Policies\Administrative Templates\Windows Components\Terminal Services node of the Group Policy Management Console.

    If you configure and link the Computer Configuration GPO to your domain level, all computers in the domain will take and apply the GPO as default. But you can use security filtering or delegation to refine which computers will receive and apply the GPO.

    By default, all GPOs have Read and AGP both Allowed for the Authenticated Users group. The Authenticated Users group includes both users and computers. This is how all authenticated users receive the settings of a new GPO when it is applied to an organizational unit, domain or site. However, you can change these permissions to limit the scope to a specific set of users, groups, or computers within the organizational unit, domain, or site.

    Or you can set GPO delegation, set deny access permission for workstations which you don’t want them to apply this GPO.

    For more information please refer to following MS articles:

    Filter using security groups
    http://technet.microsoft.com/en-us/library/cc779291(v=WS.10).aspx
    Security filtering using GPMC
    http://technet.microsoft.com/en-us/library/cc781988(v=WS.10).aspx
    Delegation and policy-related permissions
    http://technet.microsoft.com/en-us/library/cc776858(v=WS.10).aspx


    Lawrence

    TechNet Community Support

    2 มีนาคม 2555 2:03
    ผู้ดูแล
  • Hi,

    Thanks for your posting.

    Delegation can be set to any group or user.  You can set a domain local group and add workstations which you don’t want them to apply this GPO to this domain local group. And then set deny read and access permission for the domain local group.

    For more information please refer to following MS articles:

    Delegate policy-related permissions on a domain, OU, or site using GPMC
    http://technet.microsoft.com/en-us/library/cc759064(v=ws.10).aspx


    Lawrence

    TechNet Community Support

    5 มีนาคม 2555 2:42
    ผู้ดูแล

ตอบทั้งหมด