20. 4. Implementing Windows NT, Terminal Server 4.0 System Policies MetaFrame XP Servers that are members of Microsoft NT 4.0 domains and or Novell Netware environments, implement System Policies using policies files configured through the System Policy Editor. The System Policy Editor is a graphical tool provided with Windows that allows you to easily update the registry settings to customize and lockdown a particular user or group of users. The System Policy Editor creates a file that contains registry settings that are then written to the user or local machine portion of the registry database. User Profile settings that are specific to a user who logs on to a given workstation or server are written to the registry under HKEY_CURRENT_USER. Likewise, machine-specific settings are written under HKEY_LOCAL_MACHINE.  How to Set the System Policy File Share Location By default, servers reference the Ntconfig.pol located in the Netlogon share. This reference can be found in the registry, located at: HKEY_LOCAL_MACHINE\System\CurrentControlSet\ Control\Update In order to create specific policies for MetaFrame XP Servers you will need to create modify the above registry key value to point to a dedicated MetaFrame XP policy file located on a network share. The value for this registry key is modified on a computer-by-computer basis. To modify this value, I recommend you use the System Policy Editor and modify the update section found in the network section of the default machine properties. The Common.adm administrative template defines this registry key as shown below. Note: This change will need to be made on every MetaFrame XP Server that you want to take advantage of System Policies. 1. Click Start click Run type: poledit and click OK. Click File Open Registry  2. Double click on the Local Computer icon.  3. The Local Computer Properties box opens. Browse to the Remote update. (expand Network System polcies update and then check the Remote update. Choose Manual (use specific path) from the Update mode drop down box and then enter the UNC location that the system policy will be stored in the Path for manual update text box. Click OK with finished.  4. Follow steps 1 through 4 on every MetaFrame XP Server running in Application mode. You are now ready to create user and computer system polcies. 1. Click Start click Run type: poledit and click OK. 2. Click Options click Policy Template  3. Click Add  4. Browse to a Policy Template and click Open.  5. If you would like to add more Policy Templates then repeat steps 3 and 4 when finished click OK.  You are now ready to create or edit System Policies. The following procedures document how to create a system policy with the System Policy Editor utility. 1. Click Start Click Run type: poledit  2. Click Edit click Add Group  3. The Add Group dialog box will open and prompt you to enter the groups name. Click Browse to select the group  4. Select the groups you would like to add and click OK. Note: I highly recommend you add the Domain Admins group and for every change you make to a group you make the adverse change to the Domain Admins group. This will guarantee you do not lock yourself out.  5. You are now presented with the System Policy that, in this example, consists of the Default Computer, Default User, CTX Users and Domain Admins groups. Double Click on the CTX Users account to open the policy Note: The CTX Users account is a group made up of every user that has log on access to the MetaFrame XP Server. I recommend crating such a group instread of using the Domain Users group.  6. You are now presented with the CTX Users Properties and are free to configure the policy by selecting polices.  7. Now that you have imported the HideCalc Policy Template you will want to enable the policy by checking the Hide Drives as defined by Hidcalc. You will also want to make other changes as well but remember to make the adverse changes to the Domain Admins group. Click OK with finished.  8. Now you will want to make the adverse policy change to the Domain Admins group to ensure that you do not lock yourself out of any features or functions.  9. Click to uncheck any policy that was enabled in step 7. Note: An unchecked checkbox mean the policy is not enabled. A grayed out check box means it will inherit the current applied policy and a checked box means the policy is enabled.  10. Click OK. 11. Click File click Save  12. Save the policy to the policy share that was created earlier in the document.  You are now ready to test your policy and tweak them as needed. Now that we have our MetaFrame XP Server environment setup we are ready to move on to installing and configuring MetaFrame Password Manager. MetaFrame Password Manager allows end-user to authenticate once and then allow MetaFrame Password Manager to manage and secure authenticate to any application, web page and or terminal emulation session. Below we have documented the basic steps needed to deploy Password Manager utilizing the File System directory service. Please refer to the MetaFrame Password Manager 2.0 Administrators Guide for more detailed installation and configuration information. Citrix MetaFrame Password Manager is broken down in to the following three components that will need to be deployed and configured. Directory (File Sync, Microsoft Active Director) Stores configuration information MetaFrame Password Manager Console Utility used to create and configure application definitions, Agent settings and everything else associated with Password Manager. MetaFrame Password Manager Agent Is the client side component that uses an intelligent engine to recognize web sites, applications, and or terminal emulations sessions requiring authentication and password management. In order to configure the MetaFrame Password Manager Agent to synchronize with the directory service you will be required to perform the following tasks: Prepare the Directory Service File Share Microsoft Active Directory Install the Administrative Console and configure MetaFrame Password Manager. Configure Agent Settings Configure User Questions Create any required application definitions Generate MetaFrame Password Manager Agent installation program (MSI). Deploy MetaFrame Password Manger Agent Manually From Installation Manager, Active Directory and or other rapid deployment method. The following details how to perform a basic installation and configuration of MetaFrame Password Manager 2.0. |