Solved

Terminal Server

Posted on 2001-06-25
13
126 Views
Last Modified: 2010-04-13
Hello;

At our sight we have TS running. Clients cannot only log onto the TS is they are a member of the Admin group. Otherwise they get a message saying that the local policy osf this system doesnt allow you to log on interactively.
I have verified that the Domain users and the Everyone group has permission to log on locally and to access from the network. Also verified that they are not a member of any group that cannot. I cannot see what else it could be?

Thanks

Lee
0
Comment
Question by:Brazilee
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 5
  • 2
  • +1
13 Comments
 
LVL 12

Expert Comment

by:Housenet
ID: 6225646
Lee the domain policy is where you have to allow this.
-I persomally would create a group called TSUsers .. Edit the domain policy & allow TSUsers to logon locally.
-Add the users you want to TSUsers group..
-Then in RDP-TCP properties permissions.. Add TSUsers with user or guest access.
0
 
LVL 12

Expert Comment

by:Housenet
ID: 6225653
p.s unless you issue a secedit /refreshpolicy /machine_policy .you will not notice the effective setting for several minutes.
0
 

Author Comment

by:Brazilee
ID: 6225924
I did as you suggested but am still getting the same message?
0
Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

 

Author Comment

by:Brazilee
ID: 6225928
I did as you suggested but am still getting the same message?
0
 
LVL 12

Expert Comment

by:Housenet
ID: 6226170
Brazilee set it in domain controller policy as well
0
 
LVL 14

Expert Comment

by:AvonWyss
ID: 6226738
In the Administrative Tools, open the Terminal Services Configuration. Go to Connections, and open the properties of "RDP-Tcp". Go to "Permissions" tab, and set up the users/groups which should be allowed access.
0
 
LVL 11

Expert Comment

by:geoffryn
ID: 6227797
Do you have the Terminal Services installed in Remote Admin mode or Application Mode?  In Remote Admin, only members of the administrators group are allowed to connect.  You may need to change the mode and license in application mode.
0
 
LVL 14

Expert Comment

by:AvonWyss
ID: 6228085
geoffryn, while it is true that the default is only Admins can connect in Admin mode, the setting I described can still be used to allow other groups access to TS in any mode. Of course, this doesn't change the 2-user limit which is imposed by the admin mode.
0
 

Author Comment

by:Brazilee
ID: 6228223
It is running in Application mode. I gave the appropiate permissions in the TS Config. As far as setting it on the Domain controller. I set it for Local and Domain policies
0
 
LVL 12

Expert Comment

by:Housenet
ID: 6228264
Brazilee , what about domain controller policy ?
-Are you saying it still denies you access ?
0
 

Author Comment

by:Brazilee
ID: 6228376
It is running in Application mode. I gave the appropiate permissions in the TS Config. As far as setting it on the Domain controller. I set it for Local and Domain policies
0
 
LVL 12

Accepted Solution

by:
Housenet earned 100 total points
ID: 6228717
Brazilee .... There is ... Domain security policy... Domain controller security policy, & local security Policy in administrative tools...  
-Im not asking you if you set the domain policy on the domain controller.... Im asking .. Did you set the logon locally right in the "domain controller security policy"....

0
 

Author Comment

by:Brazilee
ID: 6229061
That was it-Thanks Housenet
0

Featured Post

Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
We have put together a white paper that aims to explain how MSPs can both improve their offering and ease the pain of after-hours service by: -Suggesting changes to workflow -Indicating how to rework policy to suit your team -Providing ConnectW…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question