Cannot Remote Desktop to servers Even if in Remote Desktop Users Group
So To allow my IT Staff to Remote Desktop to the Server machines without
being a Domain Admin, I followed the how to on Creating the Restricted Group
and then Adding that group to the Local Remote Desktop Users group.
The IT staff can login just fine. If I as Sam User to the Remote Desktop
Users group on the local server they are not allowed in and get the message
about having to be added to the group.
What gives? Did I setup the Restricted Group Wrong?
RE: Cannot Remote Desktop to servers Even if in Remote Desktop Users Group
If I understand correctly, you add a group IT Staff and a user account Sam
to the Remote Desktop Users group on the servers by configuring the
Restricted Group policy. You find that the user who is a member of the IT
Staff group can logon the server remotely. However, you cannot logon the
server remotely with the Sam user account and get the following message:
"To log on this remote computer, you must be granted the Allow log on
through Terminal Service right¡*"
Before we go any further, I would like to collect the following information
with you:
1. Is the user account Sam a member of the IT Staff group or Remote Desktop
Users group?
2. What operating system is running on the servers?
3. Are the servers Domain Controllers?
4. Please run the following commands on a server:
gpresult /v > gpresult.txt
net user sam /domain > sam.txt
net localgroup "remote desktop users" > group.txt
Note: Press Enter after each command.
Then, zip and upload the files above to the following space:
https://sftasia.one.microsoft.com/ch...0861-4778-4e5f
-810a-f360adbd5d5f
Password: WwQGjr3Kz179Tt
Re: Cannot Remote Desktop to servers Even if in Remote Desktop Users Group
Zip file has been uploaded
Not quite. I Created a Group called LocalAdmins in AD, then with Restricted
Group policy I added that group to the Server's Remote Desktop Users group.
I've then gone to the local Server's Remote Desktop Users group to add
additional users/groups that I would like to have the ability to remote
desktop to that server.
1. Is the user account Sam a member of the IT Staff group or Remote Desktop
Users group?
The user that is Denied is a Member of the Local Server's Remote
Desktop Users Group and is NOT a member of the IT Staff group
2. What operating system is running on the servers?
Win2003 R2 SP2
3. Are the servers Domain Controllers?
No
Re: Cannot Remote Desktop to servers Even if in Remote Desktop Users Group
I set up the Restricted group as Directed by a How-To I found. It implied
that if you added users to the Group name that it would wipe out any users
that were actually in the Group that is Manages in AD vs. the RG Policy.
Yes, Adding the RDU group to the Allow log on through Terminal Services
fixed the issue.