Thanks, the mstsc /console part works, but this is a domain controler, there are no remote users, just AD members.
Main Topics
Browse All TopicsHello, I’ve lost the ability to connect to my Windows Server 2003R2 administrative terminal server, with any domain admin account.
I get this message when I login in with any of my credentials:
To log on to this remote computer, you must have Terminal Server User access permissions on this computer. By default, members of the Remote Desktop Users group have these permissions. If you are not a member to the Remote Desktop Users group or another group that has these permissions, or it the Remote Desktop User group does not have these permissions, you must be granted these permissions manually.
There is no RDP group, because this is a mixed domain I manually added the domain administrators thru the Terminal Services Configuration.
I checked the default domain controllers GPO and all the administrator groups are in the login rights, it is the only GPO that applies.
I've rebooted twice already.
I had this problem before and it went away, and it was working as far back as last week. Is there something in the registry I can check, or should I just format this troublesome factory preloaded software, and put Windows 2003 back on myself?
Thanks- Corey
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
These are the only members of that group:
Name Type Description
Account Operators Security Group - Domain Local Members can administer domain user and group accounts
Administrators Security Group - Domain Local Administrators have complete and unrestricted access to the computer/domain
Backup Operators Security Group - Domain Local Backup Operators can override security restrictions for the sole purpose of backing up or restoring files
Guests Security Group - Domain Local Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted
Pre-Windows 2000 Compatible Access Security Group - Domain Local A backward compatibility group which allows read access on all users and groups in the domain
Print Operators Security Group - Domain Local Members can administer domain printers
Replicator Security Group - Domain Local Supports file replication in a domain
Server Operators Security Group - Domain Local Members can administer domain servers
Users Security Group - Domain Local Users are prevented from making accidental or intentional system-wide changes. Thus, Users can run certified applications, but not most legacy applications
reference to restore ad groups => http://support.microsoft.c
Business Accounts
Answer for Membership
by: usacadenaPosted on 2006-10-23 at 20:35:41ID: 17793343
try start -> run -> type "mstsc /console" -> lhit ok
log on locally
the group is found when you right click on my computer -> properties- > Remote tab- > Select remote users
make sure allow users to connect is checked off