Configure Agents for Server OS
If you use server-based computing and you want all users to log on to a session with the Ivanti Workspace Composer, you can configure this in the Microsoft Group Policy Object Custom User Interface. This will start Workspace Control as the Shell in a user session instead of the Windows Desktop.
To configure this, execute the following steps:
Step 1: Create a new Group Policy Object.
In the Microsoft Windows Group Policy Management Console, create a new Group Policy Object.
Step 2: Configure the relevant policies for the Group Policy Object

- Go to User Configuration > Administrative Templates > System
- Locate and open the object Custom User Interface
- Set to Enabled
- Under Options, specify the Interface file name as %respfdir%\pfwsmgr.exe
- Click OK to save your changes

- Go to Computer Configuration > Administrative Templates > System > Group Policy
- Locate and open the object Configure user Group Policy loopback processing mode
- Set to Enabled
- Under Options, select Replace
- Click OK to save your changes

- Go to Computer Configuration > Administrative Templates > System > Logon
- Locate and open the object Always wait for the network at computer startup and logon
- Set to Enabled
- Click OK to save your changes
Step 3: Configure security for the Group Policy Object
On the Security tab of the GPO Properties window, add the group holding all users you want a Managed Desktop for.
You can remove (or deny) the "apply-rights" for your administrator accounts. Alternatively, use the Workspace Control feature Bypass composer for accounts and groups.
If you configured the Authenticated Users group, you must also give this group Read permissions on the Group Policy Object (GPO), if KB3159398 in Microsoft Security Bulletin MS16-072 has been applied.
Step 4: Link the Group Policy Object to an OU
Select the Active Directory OU that contains your RDS Servers/Citrix Servers and link the new Group Policy Object to that OU.