2012 STD - Add RDP Role, Failure

ON 2012 STD (not r2)  Server Trying to Add the RDP Role (Session Based) get the following error.  How do I Specifically make the change needed to get around this.  Thanks.


Event 7041

The MSSQL$MICROSOFT##WID service was unable to log on as NT SERVICE\MSSQL$MICROSOFT##WID with the currently configured password due to the following error:
Logon failure: the user has not been granted the requested logon type at this computer.
 
Service: MSSQL$MICROSOFT##WID
Domain and account: NT SERVICE\MSSQL$MICROSOFT##WID
 
This service account does not have the required user right "Log on as a service."
 
User Action
 
Assign "Log on as a service" to the service account on this computer. You can use Local Security Settings (Secpol.msc) to do this. If this computer is a node in a cluster, check that this user right is assigned to the Cluster service account on all nodes in the cluster.
 
If you have already assigned this user right to the service account, and the user right appears to be removed, check with your domain administrator to find out if a Group Policy object associated with this node might be removing the right.
howmad2Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Cliff GaliherCommented:
That is one of the most descriptive error messages you can get. The "user action" section tells you what to do and even suggests what tool to use. If you launch the local security policy as it suggests, there is a list of various security privileges, and one of them will be "log on as a service." It is actually pretty tough to get more detailed than that error message already is.
0
howmad2Author Commented:
The 2012 Server is on a domain as a member server.  GPEdit from the local server has the Log on as a Service for editing grayed out.  

On the DC Group Policy Management and edited the default domain policy  / Security Settings / Local Policy / User Right Assignment / Log On as  a Service /  - was able to add the NetWork Service user and GPUpdate / Force.  

Adding Remote Desktop / Session Host fails the same way...
0
Cliff GaliherCommented:
If you look at the error, what needs the permissions is a SQL service account, not the network service. NT does not stand for network, it is the standard naming for all service accounts and the naming is a throwback to Windows NT some 20+ years ago.
0
IT Pros Agree: AI and Machine Learning Key

We’d all like to think our company’s data is well protected, but when you ask IT professionals they admit the data probably is not as safe as it could be.

howmad2Author Commented:
Cliff.  I (really) appreciate you patience....in my case...looking at my original post....what is the name of the SQL Service account and where can I find it...
0
Cliff GaliherCommented:
account: NT SERVICE\MSSQL$MICROSOFT##WID
0
howmad2Author Commented:
where do I find NT SERVICE\MSSQL$MICROSOFT##WID and what permission do I add.  Thank You.
0
Cliff GaliherCommented:
You give it the logon as service right. It should be an account already present on the local server.
0
howmad2Author Commented:
if you mean on the 2012 server intended to be the RDP server......under Computer Management  / Users......  there is no user called  MSSQL$MICROSOFT##WID
0
howmad2Author Commented:
what was needed was go to the DC.  Under Group Policy Management, Group Policy Objects, Default Domain Policy, ..... Local Policy, User Right Assignment, Log On As a Service,  I Added "NT Service/All Services".  GPUpdate/force and DC and New RDP server and run wizard Again.  

Thanks for staying with me on this..
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
howmad2Author Commented:
Found Answer on my own.  Responses didn't solve issue but were appreciated.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Remote Access

From novice to tech pro — start learning today.