Solved

Purpose of Remote Desktop GPO if machines needs to be configured locally

Posted on 2014-09-06
7
258 Views
Last Modified: 2014-09-11
Hi,

I created A GPO in my Windows server 2012 domain to allow users to connect to workstations remotely through Remote Desktop.

Following procedure had been applied: http://www.dannyeckes.com/server-2012-enable-remote-desktop-rdp-group-policy-gpo/

GPO have been updated (gpudate / force) and workstation even rebooted.

Users that have no administrator privilege cannot remotely login and get the following messages: "The connection was denied because the user account is not authorized for remote login"

I have read on different posts that the remote desktop permissions should be given locally by adding the necessary groups / users. Didn't try but that will work for sure.

I'm wondering what is then the purpose of the GPO if permissions are to be given locally !
And also, what do you do if you have 200 machines to configure !

Regards,


David
0
Comment
Question by:Urbantrax
  • 4
  • 3
7 Comments
 
LVL 56

Expert Comment

by:Cliff Galiher
Comment Utility
You usually wouldn't ever give remote access to 200 machines. Not just because of the policy issue, but because of the network traffic l, management, information security....remote desktop was never designed to be used in that way.

You'd instead set up RDSH or RDVH, and in that setup, you don't configure or touch a bunch of individual machines. Your desktops are centralized on fewer large servers. RDSH makes the necessary changes by default, and RDVH is based off an image that has been purpose-built for the task and also has the necessary changes. So touching local installs becomes a non-issue.

So basically if you are trying to allow access to 200 workstations ,chances are you are doing something wrong. And are probably breaking the software EULA in the process.
0
 

Author Comment

by:Urbantrax
Comment Utility
200 workstations is of course only an example. The goal is here to allow some users to access physical machines remotely if needed. I'm trying to understand why the GPO doesn't work or, in other words, to understand what is the purpose of such a GPO while it seems mandatory (correct me if I'm wrong) to still manually add a selection of users/domain groups on each machine.
0
 
LVL 56

Expert Comment

by:Cliff Galiher
Comment Utility
As I said, the purpose of the GPO is meant to control RDSH/RDVH servers. In those environments the GPO is an effective tool. It is NOT meant to be used how you are trying to use it, and so it is proving to be less than ideal. You are trying to use a screwdriver to pound in a nail.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Accepted Solution

by:
Urbantrax earned 0 total points
Comment Utility
Don't agree with your vision. Remote Desktop GPO already existed before RDSH/RDVH servers and it is a valid way to connect remotely to Windows workstations. I succeeded to solve the issue: It was apparently a security filtering issue (to be confirmed) or a gpupdate issue.
0
 
LVL 56

Expert Comment

by:Cliff Galiher
Comment Utility
RDSH used to be called TS, and has been built into windows just as long as group policies have, since windows 2000. So you at closjg a question when you haven't prove  your own theory (which you admit to with your "to be confirmed" comment AND your "facts" are blatantly wrong. But good luck to you. I'll remember you and won't help further since you clearly know the answer before you ever ask the question.
0
 

Author Comment

by:Urbantrax
Comment Utility
Excuse me Cliff but you simply didn't answer the original question (how can I allow some users to connect to workstations through RDP using GPOs and without having to add local security manually) and I didn't know the answer before posting. I just kept on reading and trying.

I can know confirm that the default "Authenticated Users" group in the "Security Filtering" section of the GPO needs to be replaced by the group "Remote Desktop Users" (in my case) and do a gpupdate. This wasn't described in the procedure I used as you can verify.

Before virtualization existed, it was already possible to connect to workstations through RDP using GPOs. That is all I wanted to do. So please, be a good player !
0
 

Author Closing Comment

by:Urbantrax
Comment Utility
No solution provided by member. Solved myself.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Join & Write a Comment

The article will show you how you can maintain a simple logfile of all Startup and Shutdown events on Windows servers and desktops with PowerShell. The script can be easily adapted into doing more like gracefully silencing/updating your monitoring s…
When you start your Windows 10 PC and got an "Operating system not found" error or just saw  "Auto repair for startup". After a while, you have entered a loop for Auto repair which does not fix anything and you will be in a  panic as all your work w…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
The viewer will learn how to successfully download and install the SARDU utility on Windows 7, without downloading adware.

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now