How do I ensure that a user has access to an application from my companies round robin terminal services?

Posted on 2013-11-20
Medium Priority
Last Modified: 2013-12-18
Good afternoon experts,

This will be a long message so be prepared. I have taken over the Active Directory infrastructure for the Boys  & Girls Clubs of Monterey County. Included in that take over is a hosted VWmare environment that houses 5 VM's:


My most pressing concern is that one of the users that's logs into a terminal services session is not get access to a specific  application called Trax Attendance Manager.

I have a terminal server user that  also logs in and has Trax Attendance Manager.



Both terminal servers have the software installed:





I have compared the two accounts and here are the differences.

is it a simply a matter of ensuring that they have access to the same groups or is there more to the story?

I checked all the other tabs for each of the accounts and they are identical.
Question by:BLACK THANOS
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39664897
If the user can get access to the application on one of the Terminal Servers and not the other it is probably a permission issue. Check the permisisons for the application on the terminal server/s directly and compare what groups have access. If you are using TS load balancing then the permissions need to be identical as the user could connect to either one of the servers at a given time.

I would also check the event logs as well to see why they are getting access denided. This should point out the issue.

LVL 14

Expert Comment

by:Ram Balachandran
ID: 39664946
Is round robin configured for TS - Else you can configure following http://technet.microsoft.com/en-us/library/cc772418(v=ws.10).aspx

Accepted Solution

Rahul Patil earned 2000 total points
ID: 39664982

Yes, It's simply due to group  membership of user.User is not able to access application as he has not access to that application.Please compare user group membership who have access to application.If that also not works then you can try adding individual user to application user list using application properties.

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Author Comment

ID: 39667074
I Tend to agree with rtantra, that it is a group issue, but I added the groups to the account that is not working from the account that has the trax attendance manager and the person still doesn't have the application when he logs in.

keep in mind I have just taken over this Active Directory environment , but I am still green with terminal services. There must be a permission that I am missing since both accounts are identical in their group affiliation.

Or , am I supposed to install something on the users profile? I just don't know.

Author Comment

ID: 39667991
To add further to the conversation. I went to the user program files (x86) directory and the application was installed. It just didn't show up on his start menu or program files list.

Why would that be?

Author Comment

ID: 39670770
Can anyone answer why the software didn't get pinned in the startmenu program files listings?

Author Closing Comment

ID: 39727980
Turned out to be group membership

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…
Suggested Courses
Course of the Month9 days, 5 hours left to enroll

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question