Solved

Group "Remote Desktop Users" can´t connect to W2k8 Terminal Server

Posted on 2009-03-29
4
4,526 Views
Last Modified: 2013-11-21
Hello,

i hope you can help me. I have a W2k8 Std. Terminal Server. At the moment i have the problem that no user i add localy to the "Remote Desktop Users" Group can´t connct. With my admin account i have no problems to connect but if i want to log on with a domain user i recive the message "To log on this remote computer, you must be granted ......"

At active directory the checkbox "deny this user permission to log..." for this user are not active. I started the license diagnostic on this terminal server with the result that all is ok (status green). If i take a look at the eventlog i see the following:

################################################################

System - Event ID: 1004

The terminal server cannot issue a client license.  It was unable to issue the license due to a changed (mismatched) client license, insufficient memory, or an internal error. Further details for this problem may have been reported at the client's computer.

Security - Event ID: 4625

An account failed to log on.
Account For Which Logon Failed:
Security ID: NULL SID
Account Name: testuser
Account Domain: TEST

Failure Reason: The user has not been granted the requested logon type at this machine.
Status: 0xc000015b
Sub Status: 0x0

################################################################

I have installed 20 User CALS. Both the TS server and the TS Lic server configured for User CALS.

After 2 days i have no more ideas. Did you have any idea how i can solve this problem.

Thanks
Chris
0
Comment
Question by:Quixtos
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 31

Accepted Solution

by:
Henrik Johansson earned 500 total points
ID: 24014013
The license problem: Is TS aware of the location of the TS licensing server? If TS licensing isn't located on DC, this nead to be configured by either using local Server Manager or using GPO
Computer Configuration\Policies\Administrative Templates\Windows Components\Terminal Services\Terminal Server\Licensing\Use the specified Terminal Services licensing server

The grant permission problem:
Check the policy setting includes the Remote Desktop Users and not only Administrators.
Computer Configuration\Policies\Security Settings\Local Policies\User Rights Assignment\Allow log on through Terminal Services
0
 

Author Comment

by:Quixtos
ID: 24014102
ok i see only the group "domain\domain admins" under Allow log on through Terminal Services. How can i add the local Remote Desktop Users Group?
0
 

Author Comment

by:Quixtos
ID: 24014179
I hate this Guy in my company how delete the "Remote Desktop Users" from this Policy!

TOMORROW IS D-DAY MY UNKOWN FRIEND. I WILL FIND YOU! ;o)

THANKS for the fast solution henjoh09!
0
 
LVL 31

Expert Comment

by:Henrik Johansson
ID: 24014200
Run RSOP.msc (Resultant Set Of Policies) to evaluate where the policy setting is propagated from.
After that, use Group Policy Management Console (GPMC) to set the policy setting by either edit the existing GPO or create a new GPO linked to an OU closer to the computer object.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Monitoring solutions 8 77
2008 R2 time server is invalid 6 38
NTP time source for DC 3 53
Google Chrome GPO Not Applying 5 35
I was supporting a handful of Windows 2008 (non-R2) 2 node clusters with shared quorum disks. Some had SQL 2008 installed and some were just a vendor application that we supported. For the purposes of this article it doesn’t really matter which so w…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question