Have you tried using Remote Desktop as a shell to prevent a user from being able to do anything other than an RDP session?Using mstsc.exe & additional command line options in the shell value is fine & using a restricted user to auto admin logon to the domain to fire this off is fine too. The user is only able to log on to the terminal server without running any other apps locally BUT when they end the RDP session the PC just sits there with a clear background - the user needs to ctrl-alt-del & reboot to get back to a logon prompt.I have tried the restart shell registry value too but this has no effect.Anybody got any other ideas how this can be achieved?ThanksEddie