Solved

Terminal Server ; remote control (shadowing) ; error 5 access is denied

Posted on 2011-09-19
6
2,196 Views
Last Modified: 2012-08-14
Hello;

We are seeing a problem on all Server 2008 terminal services (remote desktop services) where in certain situation, we and end users cannot "shadow" another user's terminal server session.

When trying to shadow another TS user's session via either the GUI (Administrative Tools > Terminal Services Manager > Right Click existing Session > Remote Control) or via the SHADOW command-line utility, we get the error 'access is denied'; error 5.

There are many articles out there on this error, but they all point to group policy configurations that we DONT use.  I've narrowed it down a bit by OS, it seems.  When I RDP into an affected server from a Windows 7 client (32 or 64 bit), the problem occurs.  However, when I RDP in from another Windows 2008 server (TO the same server), the problem does NOT happen.  Obviously slightly different versions of the RDP client.  I suspect its a problem with the RDP client shipped with WIndows 7.

I have also read this article ( http://support.microsoft.com/kb/2273487/en-us ) which does not apply, as all TS's in this case are Server 2008 SP2 (not R2).

Group Policies do not define any TS/RDP specific settings OTHER THAN keep-alive and session time out.  I have also tried each of the various group policy settings related to RDP compression, to no avail.

Anyone know of any solutions?  Or--at least confirmation that this is a known Microsoft bug that has yet to be fixed?  Thank you.
0
Comment
Question by:Uptime Legal Systems
  • 4
  • 2
6 Comments
 
LVL 5

Expert Comment

by:greedj
ID: 36906216
If you are not using Group Policy, you need to configure terminal services manually on the server.

Administrative tools, Remote Desktop Services, Remote Desktop Session Host Configuration.
Right click rdp-tcp and select properties.
review all settings.

Changes only apply to new rdp sessions. Any existing connection will have to logout and back in.
0
 
LVL 6

Accepted Solution

by:
Uptime Legal Systems earned 0 total points
ID: 36906351
no solution
0
 
LVL 5

Expert Comment

by:greedj
ID: 36906445
I have also seen this happen when there is a kerberos security ticket that exceeds the maximum configured size. Do you have any event log errors (Security or System) ?
0
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 6

Author Closing Comment

by:Uptime Legal Systems
ID: 37105843
abandoned
0
 
LVL 6

Author Comment

by:Uptime Legal Systems
ID: 37084018
abandoned
0
 
LVL 6

Author Comment

by:Uptime Legal Systems
ID: 37084023
abandoned
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Normally after a failure of Domain Controller, when promoting new DC the DC is renamed, we will discuss the options in Dcpromo to re-create the DC with the same name. Scenario: You are a small IT shop with two Domain Controllers (Domain Contr…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question