Solved

Purpose of Remote Desktop GPO if machines needs to be configured locally

Posted on 2014-09-06
7
269 Views
Last Modified: 2014-09-11
Hi,

I created A GPO in my Windows server 2012 domain to allow users to connect to workstations remotely through Remote Desktop.

Following procedure had been applied: http://www.dannyeckes.com/server-2012-enable-remote-desktop-rdp-group-policy-gpo/

GPO have been updated (gpudate / force) and workstation even rebooted.

Users that have no administrator privilege cannot remotely login and get the following messages: "The connection was denied because the user account is not authorized for remote login"

I have read on different posts that the remote desktop permissions should be given locally by adding the necessary groups / users. Didn't try but that will work for sure.

I'm wondering what is then the purpose of the GPO if permissions are to be given locally !
And also, what do you do if you have 200 machines to configure !

Regards,


David
0
Comment
Question by:Urbantrax
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 58

Expert Comment

by:Cliff Galiher
ID: 40307583
You usually wouldn't ever give remote access to 200 machines. Not just because of the policy issue, but because of the network traffic l, management, information security....remote desktop was never designed to be used in that way.

You'd instead set up RDSH or RDVH, and in that setup, you don't configure or touch a bunch of individual machines. Your desktops are centralized on fewer large servers. RDSH makes the necessary changes by default, and RDVH is based off an image that has been purpose-built for the task and also has the necessary changes. So touching local installs becomes a non-issue.

So basically if you are trying to allow access to 200 workstations ,chances are you are doing something wrong. And are probably breaking the software EULA in the process.
0
 

Author Comment

by:Urbantrax
ID: 40307716
200 workstations is of course only an example. The goal is here to allow some users to access physical machines remotely if needed. I'm trying to understand why the GPO doesn't work or, in other words, to understand what is the purpose of such a GPO while it seems mandatory (correct me if I'm wrong) to still manually add a selection of users/domain groups on each machine.
0
 
LVL 58

Expert Comment

by:Cliff Galiher
ID: 40307722
As I said, the purpose of the GPO is meant to control RDSH/RDVH servers. In those environments the GPO is an effective tool. It is NOT meant to be used how you are trying to use it, and so it is proving to be less than ideal. You are trying to use a screwdriver to pound in a nail.
0
Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

 

Accepted Solution

by:
Urbantrax earned 0 total points
ID: 40307843
Don't agree with your vision. Remote Desktop GPO already existed before RDSH/RDVH servers and it is a valid way to connect remotely to Windows workstations. I succeeded to solve the issue: It was apparently a security filtering issue (to be confirmed) or a gpupdate issue.
0
 
LVL 58

Expert Comment

by:Cliff Galiher
ID: 40307886
RDSH used to be called TS, and has been built into windows just as long as group policies have, since windows 2000. So you at closjg a question when you haven't prove  your own theory (which you admit to with your "to be confirmed" comment AND your "facts" are blatantly wrong. But good luck to you. I'll remember you and won't help further since you clearly know the answer before you ever ask the question.
0
 

Author Comment

by:Urbantrax
ID: 40308293
Excuse me Cliff but you simply didn't answer the original question (how can I allow some users to connect to workstations through RDP using GPOs and without having to add local security manually) and I didn't know the answer before posting. I just kept on reading and trying.

I can know confirm that the default "Authenticated Users" group in the "Security Filtering" section of the GPO needs to be replaced by the group "Remote Desktop Users" (in my case) and do a gpupdate. This wasn't described in the procedure I used as you can verify.

Before virtualization existed, it was already possible to connect to workstations through RDP using GPOs. That is all I wanted to do. So please, be a good player !
0
 

Author Closing Comment

by:Urbantrax
ID: 40316497
No solution provided by member. Solved myself.
0

Featured Post

What Is Transaction Monitoring and who needs it?

Synthetic Transaction Monitoring that you need for the day to day, which ensures your business website keeps running optimally, and that there is no downtime to impact your customer experience.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A procedure for exporting installed hotfix details of remote computers using powershell
While working, an annoying popup showing below will come and we cannot cancel or close it form the screen. The error message will come again and again.
This tutorial will walk an individual through the process of installing of Data Protection Manager on a server running Windows Server 2012 R2, including the prerequisites. Microsoft .Net 3.5 is required. To install this feature, go to Server Manager…
This Micro Tutorial will give you a basic overview of Windows Live Photo Gallery and show you various editing filters and touches to photos you can apply. This will be demonstrated using Windows Live Photo Gallery on Windows 7 operating system.

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question