Comment Re:Not sure that's the way to go (Score 1) 110
I just finished setting up a Citrix server that addressed just that. Based on group membership, we can restrict what executable you launch with file security, i.e. you have to be a member of the Office Professional group in order to run Power Point or Publisher. With a simple login script, we add the desktop and start menu shortcuts to apps that they have permissions to run, and remove them if they don't have permissions. For the client side, we are using Thinstation to PXE boot the diskless clients and automatically launch a Citrix desktop session.