Thanks for the refresher.

interestingly i'm finding the opposite to be true. if I create a new security group The article helped me to understand what it is for and how it work.Thank you very much for that.

Try to duplicate your production GPOs as closely as possible. The only thing you should add is where to find the loopback processing option, and the fact that it is enabled individually per GPO.It's found in EACH GPO under: Computer Configuration

Yes, it may be "simpler" to manage most policy at the domain level, but it can leadto lazy administration practices and make it very easy to forget about the impact of this probably meant that the loop back polciy wouldnt apply to the server and thus no other users. Loopback processing is a computer configuration setting.

Since loopback is a computer configuration setting, you will need to run GPResult from an administrative command prompt. Only the list of GPOs based on the computer object is used." Loopback mode has nothing at all to do with conflicts between computer and user configuration; there are no real conflicts. The goal is to ensure the policies you are expecting to apply are actually applying.

You could try filtering the GPO: You can filter using Computer Objects as well. Finally a very clear explanation.

Second, you should make an additional policy for those computers that will create this file (this can be done easilly, will not explain).

I have one Terminal server in one OU. The employees need to receive their normal level of access (mapped drives, redirected folders, etc.), but also need to receive access to a network printer in your office. i dissalowed any changes to the proxy settings page so users could not bypass the settings as this is how the MD wanted it setup, everything through the filter. This has been causing me many a sleepless night!

In the security filter, there is only the specific computers the GPO should be applied to.

My Loopback is set to Replace. The first is exactly the same as it was without Loopback.

you really explained that well. First time i am understanding it.

Have you tried isolating the RDS? Create an RDS OU, block inheritance, create one GPO with loopback enabled, and set the user polices in the same GPO. Good Article....Very clear with Diagrams to help understand. thank you for the excellent explanation - i

The GPRESULT will tell you which GPOs applied to the user. I belive you misunderstand how loopback policies work, because you are trying to create a special GPO that would apply different user settings depending on which computer user log on to. But this time, although we are processing user GPOs, it walks down to "Desktops" and applies User GPOs linked at "Workstations" and "Desktops".

trying to figure out how to resolve it now any ideas, thanks