KB

Loopback Policies for Managing Terminal Services

See this article about creating a loopback policy - Managing Terminal Services with Group Policy.

Make sure you deny processing for the Administrator user, so that you don't lock yourself out completely. Also make sure that you allow processing for the Terminal Server computer object, so that the loopback policy will apply.

I found that the GP wouldn't apply if I had denied it for the Administrators group. My guess is that somehow it denies processing for the computer object too. If you use the Administrator user instead, it will work. (not sure about Domain Admins)