?
Solved

Windows 2K3 Term Serv Default logon to domain and not local computer

Posted on 2006-04-28
4
Medium Priority
?
432 Views
Last Modified: 2012-08-14
I have a Win 2K3 Term Serv in a Win 2k Active Directory.  Restriction have been applied to the TS to "lock down" the box(MS whitepaper).  When are prompted for their logon credentials they are defaulted to the local computer for login and I want them to default to the domain for logon.  any ideas where I can go to set this option?
0
Comment
Question by:dbgathman
4 Comments
 
LVL 18

Expert Comment

by:PowerIT
ID: 16562388
You can define that in your thin client (where depends on the brand), or in your RDP definition when using a Windows PC (click options in the Remote Desktop connection dialog)

J.
0
 

Author Comment

by:dbgathman
ID: 16562448
We are using /TSWEB, so I need to set the preference on the server side.
0
 
LVL 3

Expert Comment

by:artthegeek
ID: 16562988
In Windows XP, you can hide the domain box AND require a UPN (User Principal Name) to log on to your domain, by setting the NoDomainUI Value Name, a REG_DWORD data type, to 1 at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon on each Windows XP domain member.  This may also be the answer for terminal services logons.

NOTE: If only the SAM account is entered, Windows XP will attempt a local logon.

NOTE: You can implement this change via group policy by defining a Shutdown script that contains:

REG ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /V NoDomainUI /T REG_DWORD /D 1 /F

I have scripted NoDomainUI.bat to set the NoDomainUI Value Name to 1 on all your Windows XP domain members.

The syntax for using NoDomainUI.bat is:

NoDomainUI [Exclude1 Exclude2 ExcludeN]

Where ExcludeX is an optional list of \\ComputerNames to bypass.

NoDomainUI.bat contains:

@echo off
setlocal
set qry=reg.exe query
set add=reg.exe add
set fnd=FINDSTR /L /I /B /V /G:"%TEMP%\NoDomainUI.TMP"
if exist "%TEMP%\NoDomainUI.TMP" del /q "%TEMP%\NoDomainUI.TMP"
:loop
if {%1}=={} goto loopend
@echo %1>>"%TEMP%\NoDomainUI.TMP"
shift
goto loop
:loopend
@echo END_OF_NoDomainUI_EXCLUSION>>"%TEMP%\NoDomainUI.TMP"
for /f "Tokens=1" %%c in ('net view^|find /i "\\"^|%fnd%') do (
 for /f "Tokens=2*" %%r in ('%qry% "%%c\HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v CurrentVersion^|find "REG_SZ"') do (
 if "%%s" EQU "5.1" @echo %%c&%add% "%%c\HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /V NoDomainUI /T REG_DWORD /D 1 /F &@echo.
 )
)
endlocal
 
Let me know if this helps!
0
 
LVL 85

Accepted Solution

by:
oBdA earned 1000 total points
ID: 16569214
Log on once locally with a domain admin account, using not the UPN but the domain dropdown box, logoff again.
Or start regedit on the terminal server, go to HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon, and set the REG_SZ value "DefaultDomainName" to the NetBIOS name of your domain.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
Please read the paragraph below before following the instructions in the video — there are important caveats in the paragraph that I did not mention in the video. If your PaperPort 12 or PaperPort 14 is failing to start, or crashing, or hanging, …
Look below the covers at a subform control , and the form that is inside it. Explore properties and see how easy it is to aggregate, get statistics, and synchronize results for your data. A Microsoft Access subform is used to show relevant calcul…

864 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question