Da steht:
"Wendet alternative Benutzereinstellungen an, wenn sich ein Benutzer an einem von dieser Einstellung betroffenen Computer anmeldet."
Wenn hier alternative Benutzereinstellungen angewendet werden, warum wendet er dann die Benutzereinstellungen der Benutzer-OUs trotzdem an ? Die Benutzer befinden sich in einer anderen OU mit anderen GPOs.
Hier mal ein Link zu einem MS-Whitepaper wo genau zu dieser Einstellung geraten wird und zwar genauso wie ich es eingestellt habe:
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=7f272fff-9a6e-40c7-b64e-7920e6ae6a0d&DisplayLang=de
Da steht:
[Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options]
• Devices: Restrict CD-ROM access to locally logged-on user only
Recommended setting: Enabled
[Computer Configuration\Administrative Templates\System\Group Policy]
• User Group Policy loopback processing mode
If the Terminal Server computer object is placed in the locked down OU, and the user account is not, loopback processing applies the restrictive user configuration policies to all users on the Terminal Server. If this policy is enabled, all users, including administrators, logging on to the Terminal Server are affected by the restrictive user configuration policies, regardless of where the user account is located. Two modes are available. Merge mode first applies to the user’s own GPO, then to the locked down policy. The lockdown policy takes precedence over the user’s GPO. Replace mode just uses the locked down policy and not the user’s own GPO. This policy is intended for restrictions based on computers instead of the user account.
If this policy is disabled, and the Terminal Server computer object is placed in the locked down OU, only the computer configuration policies is applied to the Terminal Server. Each user account must be placed into the OU to have user configuration restriction placed on that user.