Solved

Dcpromo and terminal server

Posted on 2012-03-20
4
966 Views
Last Modified: 2012-04-04
I have a terminal server that I want to add as an additional domain controller (for backup purposes). When I go to run dcpromo I get the following message:

Terminal Server is installed on this computer. Installing Active Directory on this computer will change security policy on this computer so that only Administrators will be able to log on to the computer. This is done to secure access to the computer. If you wish to allow other users to log on to this computer with Terminal Server, you will need to change the security settings in Group Policy after Active Directory has been installed.


What setting(s) in Group Policy do I need to change to allow for normal terminal server access?

P.S. I know that it is not recommended to have domain controller on the terminal server, but this is my task :)
0
Comment
Question by:goliveuk
  • 3
4 Comments
 
LVL 7

Expert Comment

by:abdulalikhan
Comment Utility
Just change the Domain Controller Policy and allow logon to terminal services for the required user/group.
0
 
LVL 7

Expert Comment

by:abdulalikhan
Comment Utility
If this is a 2008 Domain Controller, Go to Administrative tools - Local Security Policy; Go to local Policies - User Rights Assignment - Allow Logon through remote desktop services and add the required users/group.
0
 
LVL 7

Accepted Solution

by:
abdulalikhan earned 500 total points
Comment Utility
If this did not work, Open Group Policy Management Editor and Go to domain controller OU expanding it will show you 'Default Domain Controllers Policy' open the policy for editing and go to Computer Configuration - Policies - Windows Settings - Security Settings - User Rights Assignment and define 'Allow Logon through Remote Desktop Services'
0
 
LVL 70

Expert Comment

by:KCTS
Comment Utility
Its NEVER a good idea to have TS on a DC. It just throws security out of the of the door

I would question your 'task' and ask the taskmaster if they really way a DC with no security.
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Join & Write a Comment

Do you have users whose passwords are expiring and they are constantly calling you?  Well I sure did and needed a way to put an end to this.  We have a lot of remote users which would not be notified that their passwords were expiring since they wer…
Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now