1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Disabling server side drives in TS 64-bit SP2

Discussion in 'Windows Home Server' started by CQL Users, Aug 21, 2009.

  1. CQL Users

    CQL Users Guest

    Does anyone know how to explicitly deny the server side C and D drives from
    showing up on the to the clients logging in via RDP? Right now, the mapped
    local drives are showing properly, but also the server side C and D are and
    we don't want those visible.

    Any step by step instructions would be appreciated.
     
  2. Dan

    Dan Guest

    I believe that only hides the client's machine drives, not the servers.
    I've also tried that and it doesn't work but I'm not sure if group policies
    will work on remote clients. These users are coming through TS 2008 web
    interface (a hosted app solution), such as Word and Excel. They are not
    part of our domain or network, but do have an AD account to authenticate
    against the TS website.

    Here is the current config of the server: Windows 2008 64-bit SP2 running TS
    as a virtual machine (Hyper V).

    Do you suggest anything else?

    "Vera Noest [MVP]" <vera.noest@remove-this.hem.utfors.se> wrote in message
    news:Xns9C6ED31EB2BFBveranoesthemutforsse@207.46.248.16...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > There's a GPO setting for this:
    >
    > User Configuration - Administrative templates - Windows components -
    > Windows Explorer
    > "Hide these specified drives in My Computer"
    >
    > More info here:
    >
    > 231289 - Using Group Policy Objects to hide specified drives
    >
    > _________________________________________________________
    > Vera Noest
    > MCSE, CCEA, Microsoft MVP - Terminal Services
    > RDS troubleshooting:

    > ___ please respond in newsgroup, NOT by private email ___
    >
    > =?Utf-8?B?Q1FMIFVzZXJz?= <CQLUsers@discussions.microsoft.com>
    > wrote on 21 aug 2009 in
    > microsoft.public.windows.terminal_services:
    ><!--coloro:green--><span style="color:green <!--/coloro-->
    >> Does anyone know how to explicitly deny the server side C and D
    >> drives from showing up on the to the clients logging in via RDP?
    >> Right now, the mapped local drives are showing properly, but
    >> also the server side C and D are and we don't want those
    >> visible.
    >>
    >> Any step by step instructions would be appreciated. <!--colorc--><!--/colorc--><!--colorc--><!--/colorc-->
     
  3. No, this GPO setting definitively can hide the server's local
    drives, but since it is a user setting, you have to link the GPO
    either to the OU which contains the user accounts (in which case it
    will also hide their local drives on their workstations) or
    (better), link it to the OU which contains the TS machine accounts,
    and then also use loopback processing of the GPO, with the
    "Replace" setting.

    Explained here:

    231287 - Loopback Processing of Group Policy

    _________________________________________________________
    Vera Noest
    MCSE, CCEA, Microsoft MVP - Terminal Services
    RDS troubleshooting:

    ___ please respond in newsgroup, NOT by private email ___

    "Dan" <news.group@cqlcorp.net> wrote on 21 aug 2009 in
    microsoft.public.windows.terminal_services:
    <!--coloro:blue--><span style="color:blue <!--/coloro-->
    > I believe that only hides the client's machine drives, not the
    > servers. I've also tried that and it doesn't work but I'm not
    > sure if group policies will work on remote clients. These users
    > are coming through TS 2008 web interface (a hosted app
    > solution), such as Word and Excel. They are not part of our
    > domain or network, but do have an AD account to authenticate
    > against the TS website.
    >
    > Here is the current config of the server: Windows 2008 64-bit
    > SP2 running TS as a virtual machine (Hyper V).
    >
    > Do you suggest anything else?
    >
    > "Vera Noest [MVP]" <vera.noest@remove-this.hem.utfors.se> wrote
    > in message
    > news:Xns9C6ED31EB2BFBveranoesthemutforsse@207.46.248.16... <!--coloro:green--><span style="color:green <!--/coloro-->
    >> There's a GPO setting for this:
    >>
    >> User Configuration - Administrative templates - Windows
    >> components - Windows Explorer
    >> "Hide these specified drives in My Computer"
    >>
    >> More info here:
    >>
    >> 231289 - Using Group Policy Objects to hide specified drives
    >>

    >> _________________________________________________________
    >> Vera Noest
    >> MCSE, CCEA, Microsoft MVP - Terminal Services
    >> RDS troubleshooting:

    >> ___ please respond in newsgroup, NOT by private email ___
    >>
    >> =?Utf-8?B?Q1FMIFVzZXJz?= <CQLUsers@discussions.microsoft.com>
    >> wrote on 21 aug 2009 in
    >> microsoft.public.windows.terminal_services:
    >><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>> Does anyone know how to explicitly deny the server side C and
    >>> D drives from showing up on the to the clients logging in via
    >>> RDP?
    >>> Right now, the mapped local drives are showing properly, but
    >>> also the server side C and D are and we don't want those
    >>> visible.
    >>>
    >>> Any step by step instructions would be appreciated. <!--colorc--><!--/colorc--><!--colorc--><!--/colorc--><!--colorc--><!--/colorc-->
     
  4. Dan

    Dan Guest

    I've tried that and I'm pretty sure the GP settings are not being applied.
    Both local server drives show up along with any remote clients drives from
    their machine. Let me restate my environment, maybe it will clear something
    up.

    Windows 2008 TS which remote users connect to the web interface to run, let's
    say MS Word. These remote users are not tied to our company at all; we are
    simply offering remote office apps for them to run. These remote clients
    are in different states connecting via Internet.

    Thanks for your help, so far.

    "Vera Noest [MVP]" <vera.noest@remove-this.hem.utfors.se> wrote in message
    news:Xns9C6F910EB20EDveranoesthemutforsse@207.46.248.16...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > No, this GPO setting definitively can hide the server's local
    > drives, but since it is a user setting, you have to link the GPO
    > either to the OU which contains the user accounts (in which case it
    > will also hide their local drives on their workstations) or
    > (better), link it to the OU which contains the TS machine accounts,
    > and then also use loopback processing of the GPO, with the
    > "Replace" setting.
    >
    > Explained here:
    >
    > 231287 - Loopback Processing of Group Policy
    >
    > _________________________________________________________
    > Vera Noest
    > MCSE, CCEA, Microsoft MVP - Terminal Services
    > RDS troubleshooting:

    > ___ please respond in newsgroup, NOT by private email ___
    >
    > "Dan" <news.group@cqlcorp.net> wrote on 21 aug 2009 in
    > microsoft.public.windows.terminal_services:
    ><!--coloro:green--><span style="color:green <!--/coloro-->
    >> I believe that only hides the client's machine drives, not the
    >> servers. I've also tried that and it doesn't work but I'm not
    >> sure if group policies will work on remote clients. These users
    >> are coming through TS 2008 web interface (a hosted app
    >> solution), such as Word and Excel. They are not part of our
    >> domain or network, but do have an AD account to authenticate
    >> against the TS website.
    >>
    >> Here is the current config of the server: Windows 2008 64-bit
    >> SP2 running TS as a virtual machine (Hyper V).
    >>
    >> Do you suggest anything else?
    >>
    >> "Vera Noest [MVP]" <vera.noest@remove-this.hem.utfors.se> wrote
    >> in message
    >> news:Xns9C6ED31EB2BFBveranoesthemutforsse@207.46.248.16...<!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>> There's a GPO setting for this:
    >>>
    >>> User Configuration - Administrative templates - Windows
    >>> components - Windows Explorer
    >>> "Hide these specified drives in My Computer"
    >>>
    >>> More info here:
    >>>
    >>> 231289 - Using Group Policy Objects to hide specified drives
    >>>

    >>> _________________________________________________________
    >>> Vera Noest
    >>> MCSE, CCEA, Microsoft MVP - Terminal Services
    >>> RDS troubleshooting:

    >>> ___ please respond in newsgroup, NOT by private email ___
    >>>
    >>> =?Utf-8?B?Q1FMIFVzZXJz?= <CQLUsers@discussions.microsoft.com>
    >>> wrote on 21 aug 2009 in
    >>> microsoft.public.windows.terminal_services:
    >>>
    >>>> Does anyone know how to explicitly deny the server side C and
    >>>> D drives from showing up on the to the clients logging in via
    >>>> RDP?
    >>>> Right now, the mapped local drives are showing properly, but
    >>>> also the server side C and D are and we don't want those
    >>>> visible.
    >>>>
    >>>> Any step by step instructions would be appreciated. <!--colorc--><!--/colorc--><!--colorc--><!--/colorc--><!--colorc--><!--/colorc-->
     
  5. But they log in with an account that's in your domain, right? The
    GPO should apply to that account.
    Have you used RSoP (Resultant Set of Policies to see which GPOs
    apply to one of these user accounts when connecting to your TS?

    _________________________________________________________
    Vera Noest
    MCSE, CCEA, Microsoft MVP - Terminal Services
    RDS troubleshooting:
    ___ please respond in newsgroup, NOT by private email ___

    "Dan" <news.group@cqlcorp.net> wrote on 25 aug 2009 in
    microsoft.public.windows.terminal_services:
    <!--coloro:blue--><span style="color:blue <!--/coloro-->
    > I've tried that and I'm pretty sure the GP settings are not
    > being applied. Both local server drives show up along with any
    > remote clients drives from their machine. Let me restate my
    > environment, maybe it will clear something up.
    >
    > Windows 2008 TS which remote users connect to the web interface
    > to run, let's say MS Word. These remote users are not tied to
    > our company at all; we are simply offering remote office apps
    > for them to run. These remote clients are in different states
    > connecting via Internet.
    >
    > Thanks for your help, so far.
    >
    > "Vera Noest [MVP]" <vera.noest@remove-this.hem.utfors.se> wrote
    > in message
    > news:Xns9C6F910EB20EDveranoesthemutforsse@207.46.248.16... <!--coloro:green--><span style="color:green <!--/coloro-->
    >> No, this GPO setting definitively can hide the server's local
    >> drives, but since it is a user setting, you have to link the
    >> GPO either to the OU which contains the user accounts (in which
    >> case it will also hide their local drives on their
    >> workstations) or (better), link it to the OU which contains the
    >> TS machine accounts, and then also use loopback processing of
    >> the GPO, with the "Replace" setting.
    >>
    >> Explained here:
    >>
    >> 231287 - Loopback Processing of Group Policy
    >>

    >> _________________________________________________________
    >> Vera Noest
    >> MCSE, CCEA, Microsoft MVP - Terminal Services
    >> RDS troubleshooting:

    >> ___ please respond in newsgroup, NOT by private email ___
    >>
    >> "Dan" <news.group@cqlcorp.net> wrote on 21 aug 2009 in
    >> microsoft.public.windows.terminal_services:
    >><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>> I believe that only hides the client's machine drives, not the
    >>> servers. I've also tried that and it doesn't work but I'm not
    >>> sure if group policies will work on remote clients. These
    >>> users are coming through TS 2008 web interface (a hosted app
    >>> solution), such as Word and Excel. They are not part of our
    >>> domain or network, but do have an AD account to authenticate
    >>> against the TS website.
    >>>
    >>> Here is the current config of the server: Windows 2008 64-bit
    >>> SP2 running TS as a virtual machine (Hyper V).
    >>>
    >>> Do you suggest anything else?
    >>>
    >>> "Vera Noest [MVP]" <vera.noest@remove-this.hem.utfors.se>
    >>> wrote in message
    >>> news:Xns9C6ED31EB2BFBveranoesthemutforsse@207.46.248.16...
    >>>> There's a GPO setting for this:
    >>>>
    >>>> User Configuration - Administrative templates - Windows
    >>>> components - Windows Explorer
    >>>> "Hide these specified drives in My Computer"
    >>>>
    >>>> More info here:
    >>>>
    >>>> 231289 - Using Group Policy Objects to hide specified drives
    >>>>

    >>>> _________________________________________________________
    >>>> Vera Noest
    >>>> MCSE, CCEA, Microsoft MVP - Terminal Services
    >>>> RDS troubleshooting:

    >>>> ___ please respond in newsgroup, NOT by private email ___
    >>>>
    >>>> =?Utf-8?B?Q1FMIFVzZXJz?= <CQLUsers@discussions.microsoft.com>
    >>>> wrote on 21 aug 2009 in
    >>>> microsoft.public.windows.terminal_services:
    >>>>
    >>>>> Does anyone know how to explicitly deny the server side C
    >>>>> and D drives from showing up on the to the clients logging
    >>>>> in via RDP?
    >>>>> Right now, the mapped local drives are showing properly,
    >>>>> but
    >>>>> also the server side C and D are and we don't want those
    >>>>> visible.
    >>>>>
    >>>>> Any step by step instructions would be appreciated. <!--colorc--><!--/colorc--><!--colorc--><!--/colorc--><!--colorc--><!--/colorc-->
     
  6. Dan

    Dan Guest

    Yes and it shows that none of the policies are being applied to the client
    workstation. This is also true on a test internal workstation that is part
    of the domain, meaning the policies to hide the drives/loopback don't get
    applied. Which to me seems right, as I'm logged into the client machine as
    a different domain user then what I'm connecting with via the website
    (TS2000).

    I guess, I don't understand how group policy settings would take effect on a
    non-domain member workstation.

    "Vera Noest [MVP]" <vera.noest@remove-this.hem.utfors.se> wrote in message
    news:Xns9C72D7711527Cveranoesthemutforsse@207.46.248.16...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > But they log in with an account that's in your domain, right? The
    > GPO should apply to that account.
    > Have you used RSoP (Resultant Set of Policies to see which GPOs
    > apply to one of these user accounts when connecting to your TS?
    >
    > _________________________________________________________
    > Vera Noest
    > MCSE, CCEA, Microsoft MVP - Terminal Services
    > RDS troubleshooting:
    > ___ please respond in newsgroup, NOT by private email ___
    >
    > "Dan" <news.group@cqlcorp.net> wrote on 25 aug 2009 in
    > microsoft.public.windows.terminal_services:
    ><!--coloro:green--><span style="color:green <!--/coloro-->
    >> I've tried that and I'm pretty sure the GP settings are not
    >> being applied. Both local server drives show up along with any
    >> remote clients drives from their machine. Let me restate my
    >> environment, maybe it will clear something up.
    >>
    >> Windows 2008 TS which remote users connect to the web interface
    >> to run, let's say MS Word. These remote users are not tied to
    >> our company at all; we are simply offering remote office apps
    >> for them to run. These remote clients are in different states
    >> connecting via Internet.
    >>
    >> Thanks for your help, so far.
    >>
    >> "Vera Noest [MVP]" <vera.noest@remove-this.hem.utfors.se> wrote
    >> in message
    >> news:Xns9C6F910EB20EDveranoesthemutforsse@207.46.248.16...<!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>> No, this GPO setting definitively can hide the server's local
    >>> drives, but since it is a user setting, you have to link the
    >>> GPO either to the OU which contains the user accounts (in which
    >>> case it will also hide their local drives on their
    >>> workstations) or (better), link it to the OU which contains the
    >>> TS machine accounts, and then also use loopback processing of
    >>> the GPO, with the "Replace" setting.
    >>>
    >>> Explained here:
    >>>
    >>> 231287 - Loopback Processing of Group Policy
    >>>

    >>> _________________________________________________________
    >>> Vera Noest
    >>> MCSE, CCEA, Microsoft MVP - Terminal Services
    >>> RDS troubleshooting:

    >>> ___ please respond in newsgroup, NOT by private email ___
    >>>
    >>> "Dan" <news.group@cqlcorp.net> wrote on 21 aug 2009 in
    >>> microsoft.public.windows.terminal_services:
    >>>
    >>>> I believe that only hides the client's machine drives, not the
    >>>> servers. I've also tried that and it doesn't work but I'm not
    >>>> sure if group policies will work on remote clients. These
    >>>> users are coming through TS 2008 web interface (a hosted app
    >>>> solution), such as Word and Excel. They are not part of our
    >>>> domain or network, but do have an AD account to authenticate
    >>>> against the TS website.
    >>>>
    >>>> Here is the current config of the server: Windows 2008 64-bit
    >>>> SP2 running TS as a virtual machine (Hyper V).
    >>>>
    >>>> Do you suggest anything else?
    >>>>
    >>>> "Vera Noest [MVP]" <vera.noest@remove-this.hem.utfors.se>
    >>>> wrote in message
    >>>> news:Xns9C6ED31EB2BFBveranoesthemutforsse@207.46.248.16...
    >>>>> There's a GPO setting for this:
    >>>>>
    >>>>> User Configuration - Administrative templates - Windows
    >>>>> components - Windows Explorer
    >>>>> "Hide these specified drives in My Computer"
    >>>>>
    >>>>> More info here:
    >>>>>
    >>>>> 231289 - Using Group Policy Objects to hide specified drives
    >>>>>

    >>>>> _________________________________________________________
    >>>>> Vera Noest
    >>>>> MCSE, CCEA, Microsoft MVP - Terminal Services
    >>>>> RDS troubleshooting:

    >>>>> ___ please respond in newsgroup, NOT by private email ___
    >>>>>
    >>>>> =?Utf-8?B?Q1FMIFVzZXJz?= <CQLUsers@discussions.microsoft.com>
    >>>>> wrote on 21 aug 2009 in
    >>>>> microsoft.public.windows.terminal_services:
    >>>>>
    >>>>>> Does anyone know how to explicitly deny the server side C
    >>>>>> and D drives from showing up on the to the clients logging
    >>>>>> in via RDP?
    >>>>>> Right now, the mapped local drives are showing properly,
    >>>>>> but
    >>>>>> also the server side C and D are and we don't want those
    >>>>>> visible.
    >>>>>>
    >>>>>> Any step by step instructions would be appreciated. <!--colorc--><!--/colorc--><!--colorc--><!--/colorc--><!--colorc--><!--/colorc-->
     

Share This Page