Prevent license upgrade

This policy setting allows you to specify which version of Remote Desktop Services client access license (RDS CAL) a Remote Desktop Services license server will issue to clients connecting to RD Session Host servers running other Windows-based operating systems. A license server attempts to provide the most appropriate RDS or TS CAL for a connection. For example a Windows Server 2008 license server will try to issue a Windows Server 2008 TS CAL for clients connecting to a terminal server running Windows Server 2008 and will try to issue a Windows Server 2003 TS CAL for clients connecting to a terminal server running Windows Server 2003. By default if the most appropriate RDS CAL is not available for a connection a Windows Server 2008 license server will issue a Windows Server 2008 TS CAL if available to the following:* A client connecting to a Windows Server 2003 terminal server* A client connecting to a Windows 2000 terminal serverIf you enable this policy setting the license server will only issue a temporary RDS CAL to the client if an appropriate RDS CAL for the RD Session Host server is not available. If the client has already been issued a temporary RDS CAL and the temporary RDS CAL has expired the client will not be able to connect to the RD Session Host server unless the RD Licensing grace period for the RD Session Host server has not expired. If you disable or do not configure this policy setting the license server will exhibit the default behavior noted earlier.

Limit number of connections

Specifies whether Remote Desktop Services limits the number of simultaneous connections to the server. You can use this setting to restrict the number of Remote Desktop Services sessions that can be active on a server. If this number is exceeded addtional users who try to connect receive an error message telling them that the server is busy and to try again later. Restricting the number of sessions improves performance because fewer sessions are demanding system resources. By default RD Session Host servers allow an unlimited number of Remote Desktop Services sessions and Remote Desktop for Administration allows two Remote Desktop Services sessions. To use this setting enter the number of connections you want to specify as the maximum for the server. To specify an unlimited number of connections type 999999. If the status is set to Enabled the maximum number of connections is limited to the specified number consistent with the version of Windows and the mode of Remote Desktop Services running on the server. If the status is set to Disabled or Not Configured limits to the number of connections are not enforced at the Group Policy level. Note: This setting is designed to be used on RD Session Host servers (that is on servers running Windows with Remote Desktop Session Host role service installed).

Remove “Disconnect” option from Shut Down dialog

This policy setting allows you to remove the “Disconnect” option from the Shut Down Windows dialog box in Remote Desktop Services sessions. You can use this policy setting to prevent users from using this familiar method to disconnect their client from an RD Session Host server. If you enable this policy setting “Disconnect” does not appear as an option in the drop-down list in the Shut Down Windows dialog box. If you disable or do not configure this policy setting “Disconnect” is not removed from the list in the Shut Down Windows dialog box. Note: This policy setting affects only the Shut Down Windows dialog box. It does not prevent users from using other methods to disconnect from a Remote Desktop Services session. This policy setting also does not prevent disconnected sessions at the server. You can control how long a disconnected session remains active on the server by configuring the “Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> RD Session Host -> Session Time Limits -> Set time limit for disconnected sessions” policy setting.

Remove Windows Security item from Start menu

Specifies whether to remove the Windows Security item from the Settings menu on Remote Desktop clients. You can use this setting to prevent inexperienced users from logging off from Remote Desktop Services inadvertently. If the status is set to Enabled Windows Security does not appear in Settings on the Start menu. As a result users must type a security attention sequence such as CTRL+ALT+END to open the Windows Security dialog box on the client computer. If the status is set to Disabled or Not Configured Windows Security remains in the Settings menu.

Suspend user sign-in to complete app registration

This policy setting allows you to specify whether the app registration is completed before showing the Start screen to the user. By default when a new user signs in to a computer the Start screen is shown and apps are registered in the background. However some apps may not work until app registration is complete. If you enable this policy setting user sign-in is blocked for up to 6 minutes to complete the app registration. You can use this policy setting when customizing the Start screen on Remote Desktop Session Host servers. If you disable or do not configure this policy setting the Start screen is shown and apps are registered in the background.

Set rules for remote control of Remote Desktop Services user sessions

If you enable this policy setting administrators can interact with a user’s Remote Desktop Services session based on the option selected. Select the desired level of control and permission from the options list:1. No remote control allowed: Disallows an administrator to use remote control or view a remote user session. 2. Full Control with user’s permission: Allows the administrator to interact with the session with the user’s consent. 3. Full Control without user’s permission: Allows the administrator to interact with the session without the user’s consent. 4. View Session with user’s permission: Allows the administrator to watch the session of a remote user with the user’s consent. 5. View Session without user’s permission: Allows the administrator to watch the session of a remote user without the user’s consent. If you disable this policy setting administrators can interact with a user’s Remote Desktop Services session with the user’s consent.

Restrict Remote Desktop Services users to a single Remote Desktop Services session

This policy setting allows you to restrict users to a single Remote Desktop Services session. If you enable this policy setting users who log on remotely by using Remote Desktop Services will be restricted to a single session (either active or disconnected) on that server. If the user leaves the session in a disconnected state the user automatically reconnects to that session at the next logon. If you disable this policy setting users are allowed to make unlimited simultaneous remote connections by using Remote Desktop Services. If you do not configure this policy setting this policy setting is not specified at the Group Policy level.

Start a program on connection

Configures Remote Desktop Services to run a specified program automatically upon connection. You can use this setting to specify a program to run automatically when a user logs on to a remote computer. By default Remote Desktop Services sessions provide access to the full Windows desktop unless otherwise specified with this setting by the server administrator or by the user in configuring the client connection. Enabling this setting overrides the “Start Program” settings set by the server administrator or user. The Start menu and Windows Desktop are not displayed and when the user exits the program the session is automatically logged off. To use this setting in Program path and file name type the fully qualified path and file name of the executable file to be run when the user logs on. If necessary in Working Directory type the fully qualified path to the starting directory for the program. If you leave Working Directory blank the program runs with its default working directory. If the specified program path file name or working directory is not the name of a valid directory the RD Session Host server connection fails with an error message. If the status is set to Enabled Remote Desktop Services sessions automatically run the specified program and use the specified Working Directory (or the program default directory if Working Directory is not specified) as the working directory for the program. If the status is set to Disabled or Not Configured Remote Desktop Services sessions start with the full desktop unless the server administrator or user specify otherwise. (See “Computer Configuration -> Administrative Templates -> System -> Logon -> Run these programs at user logon” setting. )Note: This setting appears in both Computer Configuration and User Configuration. If both settings are configured the Computer Configuration setting overrides.

Do not allow local administrators to customize permissions

This policy setting specifies whether to disable the administrator rights to customize security permissions for the Remote Desktop Session Host server. You can use this setting to prevent administrators from making changes to the user groups allowed to connect remotely to the RD Session Host server. By default administrators are able to make such changes. If you enable this policy setting the default security descriptors for existing groups on the RD Session Host server cannot be changed. All the security descriptors are read-only. If you disable or do not configure this policy setting server administrators have full read/write permissions to the user security descriptors by using the Remote Desktop Session WMI Provider. Note: The preferred method of managing user access is by adding a user to the Remote Desktop Users group.

Always show desktop on connection

This policy setting determines whether the desktop is always displayed after a client connects to a remote computer or an initial program can run. It can be used to require that the desktop be displayed after a client connects to a remote computer even if an initial program is already specified in the default user profile Remote Desktop Connection Remote Desktop Services client or through Group Policy. If you enable this policy setting the desktop is always displayed when a client connects to a remote computer. This policy setting overrides any initial program policy settings. If you disable or do not configure this policy setting an initial program can be specified that runs on the remote computer after the client connects to the remote computer. If an initial program is not specified the desktop is always displayed on the remote computer after the client connects to the remote computer. Note: If this policy setting is enabled then the “Start a program on connection” policy setting is ignored.