Solved

How does a domain user RDP into a server?

Posted on 2011-03-07
9
525 Views
Last Modified: 2013-11-21
We have quick books installed on a member server.  We need a user to remote into this server in order to access quick books from a remote office.  Their is a VPN setup and they can remote in but when they do, it states that they need to be part of the remote desktop groups.  How can we allow this user to remote in without having to give them admin access to this server to remote in?
0
Comment
Question by:maximus7569
  • 3
  • 2
  • 2
  • +2
9 Comments
 
LVL 2

Assisted Solution

by:xchange
xchange earned 250 total points
ID: 35062156
On the member server:
Right-click "My computer" | Manager
"Local Users and Groups"
add the user into the "remote desktop users" group.
0
 
LVL 33

Accepted Solution

by:
paulmacd earned 250 total points
ID: 35062174
On the member server, right-click on "My Computer" or go to Start -> Programs - > Administrative Tools and select "Manager your server"

In the Computer Management utility, select Local Users and Groups, then Groups.  On the right-hand side you'll see a list of local groups.  One is Remote Desktop Users.  Open that group and add the user's domain account to the group. That should do it.
0
 

Author Comment

by:maximus7569
ID: 35062319
Thanks guys that did the trick.  Now will that keep them from installing anything or making any changes?
0
 
LVL 33

Expert Comment

by:paulmacd
ID: 35063746
Depends on what you mean.  Adding users to the Remote Desktop Users group gives them the ability to remote in, but doesn't necessarily give them elevated permissions on the machine.  Their local permissions will depend on who they log in as.  As such, if the user is just a User (as opposed to a Power User or Administrator or somesuch), then they can only do things users can do.
0
 
LVL 16

Expert Comment

by:Shaik M. Sajid
ID: 35067898
the scenario seems to be very...

server by default can access only  2 sessions.

if u want to access more than 2 sessions u need terminal server ...

try this ... microsoft giving free access of 90 days terminal server license.

to install the terminal server see this article

http://wn.com/Windows_Server_2003__Terminal_Server_Installation

then the second option is publishin you application (quick books)  to terminal server to access remote users...
see this link.
http://wn.com/Terminal_server_configuration

there are lot of third party applications to publish your app to access remotely...

i.E   Citrix Xenapp   www.citrix.com

const effactive and good in performance   2x application server   www.2x.com
0
 

Author Comment

by:maximus7569
ID: 35069617
This is for server 2008, do you have links for that?
0
 
LVL 27

Expert Comment

by:Steve
ID: 35072194
I agree with shaiksaj. This is a bit odd.

Unless you have terminal server licenses, the server is only able to perform RDP sessions for administration. You cannot properly prevent this user from making changes without issues.

Either install terminal server licenses or change you plan asap. users logging onto servers is always a bad plan.

If you are unsure, log in as the user and try to change something. If it lets you, they could potentially shut the server down, change config or completely screw it up.
0
 

Author Comment

by:maximus7569
ID: 35088273
Thanks guys!  I will setup terminal server.  Who gets the points?
0
 
LVL 27

Expert Comment

by:Steve
ID: 35100071
It's up to you mate. choose which answer (or answers) helped you the most.

Glad you've come to a decision. Users logging into server is always a recipe for disaster....
0

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
scripting 6 53
Powershell script update 2 30
active directory 17 35
How to place a condition in a filter criteria in t-sql (#2)? 10 20
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now