Re: The local policy of this system does not allow you to log on interactively

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 02/15/05


Date: Tue, 15 Feb 2005 12:28:25 -0600

You still can add any domain user to the Remote Desktop Users group on the
Terminal Server [assuming the TS is a domain computer]. Logon to the TS as
an administrators and use local users and groups and then add the users that
you want to access this server to the local Remote Desktop Users group [make
sure to select domain in "look in". If the user exists on the DC he is a
domain user. If the TS is not a domain member, only users in the TS local
users and groups will be able to access the TS after you add them to the
Remote Desktop Users group. If this is a domain computer and you can not add
domain users, then you may be having a connectivity problem, secure channel
problem, or name resolution problem to a domain controller and running the
support tool netdiag on the TS server would be a good idea to do to check on
those issues looking for pertinent failed tests. --- Steve

"Josh" <mrblonde@ameritech.net> wrote in message
news:1108489398.380443.190660@c13g2000cwb.googlegroups.com...
>
> Steven L Umbach wrote:
>> On the Terminal Server, what is the effective setting for allow logon
>
>> through terminal services and deny logon through terminal services,
> what
>> users and groups are included??
>
> Administrators and Remote Desktop Users. I cannot add the user to this
> area or to the group Remote Desktop Users on this Server because he
> exists on the DC and does not exist on this server. In other words,
> when I log on to the TS, I am logging on to the Domain.
>
>>The deny user right will always override the
>> allow user right for a user or a group. ---Steve
>
> The deny settings are not defined
>
>>
>> "Josh" <mrblonde@ameritech.net> wrote in message
>> news:1108429730.567870.105400@z14g2000cwz.googlegroups.com...
>> >
>> > Don Wilwol wrote:
>> >> Try to open a desktop session, right from the desktop of the
> server.
>> >
>> > If I do that from the Terminal Server, type the username and
> password
>> > and select the domain, I get the error
>> >
>> > If I do that from the DC, type the username and password and select
> the
>> > domain, I get the error
>> >
>> > I cannot select (this computer) from the log on to: area because
> that
>> > user name does not exist on the Terminal Server Computer and I will
> get
>> > an error. The Terminal Server and DC are two seperate PC's.
>> >
>



Relevant Pages

  • Re: TS logon
    ... MCSE, CCEA, Microsoft MVP - Terminal Server ... I can't add "doman" remote desktop users group ...
    (microsoft.public.windows.terminal_services)
  • Re: Remote Desktop Users not able to connect to Terminal Server
    ... Did you add the users to the *local* Remote Desktop Users group on ... MCSE, CCEA, Microsoft MVP - Terminal Server ... Allow log on through terminal services right. ...
    (microsoft.public.windows.terminal_services)
  • Re: Remote Desktop Users not able to connect to Terminal Server
    ... I added the users on the domain server to the Remote Desktop Users group. ... Allow log on through terminal services right. ...
    (microsoft.public.windows.terminal_services)
  • Re: Just administrator can access TS
    ... Check RDP-TCP in the TS Config snap-in and confirm that Remote Desktop Users is there and has appropriate rights. ... Microsoft MVP - Terminal Server ... Special privileges assigned to new logon: ...
    (microsoft.public.windows.terminal_services)
  • Re: remote desktop users group
    ... This is ONLY a local group. ... In our case we had a terminal server that had been in service for over 6 months and last week the users started reporting that they could not log into it. ... If I add them to the domain Remote Desktop Users group they cannot log in even if I set the domain Login To Terminal server policy to allow it. ...
    (microsoft.public.windows.terminal_services)

Quantcast