Re: Can connect via Remote Desktop

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 09/27/05


Date: Mon, 26 Sep 2005 19:37:31 -0500

Try to access the server via RDP as the local built in administrator account
on that server - not a domain account to see if that works. By default the
group administrators and remote desktop users should have the allow logon
through terminal services user right and any entries in the deny logon
through terminal services user right will override the corresponding allow
user right. Also make sure that Remote Desktop is enabled on the server. If
you can logon via the local administrator account but not domain account
check the membership of the local administrators group on the server to make
sure it is what you expect which would include the domain admins group by
default and run the support tool netdiag on it to see if there any problems
with dns, dc discovery, trust/secure channel, etc. --- Steve

"Mike Bailey" <mbailey@beaumontproducts.com> wrote in message
news:ed65OerwFHA.2516@TK2MSFTNGP12.phx.gbl...
> I'm running 2003 servers in one domain. One server is PDC, DNS, DHCP, one
> is a file server, and this new one is a file server also running IIS. I
> can't connect to my new server via Remote Desktop. I can connect to both
> of the other servers. I get the error:
>
> "To log on to this computer you must by granted the Log On through
> Terminal Services right. By default, members of the Remote Desktop Users
> group have this right..."
>
> On the PDC, I have Administrators added to this built-in group. I also
> verified that the server is a member of the Domain (it is logion ginto the
> doamin using the domain admin suerid/pswd)
>
> On the new server the Local Security policy shows the built-in group
> Remote Desktop Users for the Log on using Terminal services policy.
>
> I've even added the Administrator to the Log on Locally policy and I still
> can't connect.
>
> I have screen shots of all these if anyone wants/needs to see them, I can
> send them to you since I can't attach here.
>
> Thanks,
> Mike Bailey



Relevant Pages

  • Re: Had to add Administrator to Remote Desktop Users group to use
    ... If you set the user right "Allow logon through terminal services" to ... changed it back to "not defined", ran gpupdate, and removed the administrator ... from the remote desktop users group, and now I can login as any domain admin. ... the terminal server, and they can login to the terminal server fine. ...
    (microsoft.public.windows.terminal_services)
  • Re: Web Server - User Access and Priviledges.
    ... It makes sense to have more than the built in administrator account. ... For the IIS 5.0 server be sure to consider ... running the IIS Lockdown/URLscan tool if you have not already but I would recommend ...
    (microsoft.public.win2000.termserv.clients)
  • Re: Web Server - User Access and Priviledges.
    ... It makes sense to have more than the built in administrator account. ... For the IIS 5.0 server be sure to consider ... running the IIS Lockdown/URLscan tool if you have not already but I would recommend ...
    (microsoft.public.windows.server.security)
  • Re: Web Server - User Access and Priviledges.
    ... It makes sense to have more than the built in administrator account. ... For the IIS 5.0 server be sure to consider ... running the IIS Lockdown/URLscan tool if you have not already but I would recommend ...
    (microsoft.public.security)
  • Re: Web Server - User Access and Priviledges.
    ... It makes sense to have more than the built in administrator account. ... For the IIS 5.0 server be sure to consider ... running the IIS Lockdown/URLscan tool if you have not already but I would recommend ...
    (microsoft.public.inetserver.iis.security)

Quantcast