• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 4043
  • Last Modified:

To log on to this remote computer, you must be granted the allow log on through Terminal Services right. By default, members of the Remote Desktop User group have this right.

server - 2003 DC
I didn't modify the defautl admin account. I also created another domain admin account. The acooung is able to remote access, but the default admin account is not..... why?

by default it should be already in the remote desktop GP, I also tried to added in the GP, but not helpful.
0
bubuko
Asked:
bubuko
  • 3
  • 2
  • 2
  • +1
1 Solution
 
QuetzalCommented:
Run Terminal Services configuration, right-click the connection, click on Properites, view Security tab.  Is the default admin account explicitly denied here?
0
 
bubukoAuthor Commented:
there is no security tab, only Permission.

In side the tab, there is Administrators, local service, network service, remote desktop users and system.

The weired thing is the other admin account which I created later is able to RDP, but the default admin (administrator) account not able to.
0
 
Michael KnightCommented:
If you're certain the users have the "allow log on the through Terminal Services" rights Then I would check the settings in the Terminal Services snap-in to ensure those users explicitly have logon locally and logon to terminal services rights..
Ive seen it a few times on 2k3 where simply adding them in AD didn't let them login to TS.
0
Easily manage email signatures in Office 365

Managing email signatures in Office 365 can be a challenging task if you don't have the right tool. CodeTwo Email Signatures for Office 365 will help you implement a unified email signature look, no matter what email client is used by users. Test it for free!

 
Michael KnightCommented:
wow too slow...jeez
0
 
QuetzalCommented:
Michael, nice catch on the user rights assignments.  This is accessible through the Local Security Policy applet.  Also check Deny logon through Terminal Services to make certain the admin account is not there.
0
 
bubukoAuthor Commented:
michaelaknight!! you rock!! I checked in DC policy, user right assignments:

Check "Allow log on locally" -> administrators is there.

Check in "Allow logon through terminal service" -> Only the created admin account is there. I removed it, instead I add the administrator GP.

But why this is not there by default?? It should be there by default though!!
0
 
Michael KnightCommented:
Hah! i wasn't too slow.
you know bubuko, I've stopped trying to understand why microsoft does what it does...I just fix the errors and collect my check ;)
0
 
AmericomCommented:
Hummm...if you are referring to a domain controller, by default, the "Domain Policy" and the "Domain Controller Policy" of the "allow log on trhough Terminal Services" are set to "Not Defined" which means only Administrator can logon remotely. This inlcuding the domain "Administrator" account as well as any domain account created as a member of Domain Admins. However, by default the local policy of the Domain Controllers(if ran gpedit.msc) of the "Allow log on through Terminal Services" is open to the "Administrators" and "Domain Admins" group. This means non administrator cannot logon remotely, even if the are added to the domain "remote desktop users" group. This is by design and usually not recommended to make your Domain Controller a Terminal Servers for security reason.

If you find any of the setting that is different then the default, then someone must have changed, either intentionally or not fully understand the different between a Domain Controller when compare to the member server.

Of course the default setting for "Allow log on through Terminal Services" is open to "Administrators" and "Remote Desktop Users" which means as long as you add a non-admin account to the Remote Desktop Users group, the user would have remote logon access to the member server.
0

Featured Post

Never miss a deadline with monday.com

The revolutionary project management tool is here!   Plan visually with a single glance and make sure your projects get done.

  • 3
  • 2
  • 2
  • +1
Tackle projects and never again get stuck behind a technical roadblock.
Join Now