Solved

To log on to this remote computer, you must be granted the allow log on through Terminal Services right. By default, members of the Remote Desktop User group have this right.

Posted on 2008-10-02
5
2,111 Views
Last Modified: 2013-11-21
Hi,
We have 2 servers in our network. Server A and B (both windows standard server 2003). Till yesterday Server B used to act as AD and terminal server in remote admin mode.  We need more than 2 users to login at the same time; we added a new server C to the network. Server C is windows 2003 standard server. To add the server C, we just made the computer part of the domain. I am not sure if I need to do something else to make it a member domain.
We routed the remote traffic to server C. We have a weird problem. When we go to secpol.msc and go to allow logon to remote access properties (see file attached). the add group is in gray;;its not letting add any users. We tried adding users thru RDP permissions; IT shows the users on secpol.msc for a couple of hours; the users can logon during this period. After the 2 hours the list of users is getting deleted and users are getting the message in the subject line...
any help greatly appreciated...
remote.doc
0
Comment
Question by:arsmed840
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 18

Accepted Solution

by:
Americom earned 250 total points
ID: 22625005
It seems like on your Server B which is now a Domain Controller, you may have enabled the "Logon through Terminal Services on your default Domain Policy. If this is applied to your domain, it will affect all servers and workstations. If Server C is a member server then that's why the option is greyed out.
Server B is an AD and should not be a Terminal Server. You can set the default domain policy to "Not Defined" then it will allow you to make change locally on Server C.
0
 

Author Comment

by:arsmed840
ID: 22625075
Hi Americom,
Could you please tell me where I can check the option "Logon through Terminal Services " is set on the DC ? I dont want this to act as terminal server anymore. I want this role to be passed to server C.
0
 

Assisted Solution

by:stasila2010
stasila2010 earned 250 total points
ID: 22770790
Domain Controllers Policy,  Windows Settings / Security Settings / Local Policies / User Rights Assignment. Allow logon through Terminal Services.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Have you considered what group policies are backwards and forwards compatible? Windows Active Directory servers and clients use group policy templates to deploy sets of policies within your domain. But, there is a catch to deploying policies. The…
INTRODUCTION The purpose of this document is to demonstrate the Installation and configuration of the Data Protection Manager product. Note that this demonstration was prepared on the basis of Windows OS is 2008 R2 and DPM 2010. DATA PROTECTI…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question