Solved

can't RDP into server 2012 server in a workgroup (not on domain)

Posted on 2014-11-26
7
668 Views
1 Endorsement
Last Modified: 2015-01-18
I have a 2012 Server that is not on a domain, it is in a workgroup. I have a computer on the same LAN/SUBNET and I cannot log into it remotely. I get the following error:

To sign in remotely, you need the right to sign in through Remote Desktop Services. By default, members of the Remote Desktop Users group have this right. If the group you're in doesn't have this right, or if the right has been removed from the Remote Desktop Users group, you need to be granted this right manually.

Remote Services is enabled on this server.
1
Comment
Question by:Gelly77
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 88

Expert Comment

by:rindi
ID: 40466907
Have you added the user to the remote desktop user's group, as suggested in the message you got?
0
 
LVL 3

Assisted Solution

by:TropicalBound
TropicalBound earned 166 total points
ID: 40466912
To grant this access, open the Local Security Policy

Expand Local Policies and select User Rights Assignment.  Right click on the policy named “Allow log on through Remote Desktop Services” and select Properties.

Add the user(s) to the policy.

TB
0
 
LVL 96

Assisted Solution

by:Lee W, MVP
Lee W, MVP earned 334 total points
ID: 40466985
While TropicalBound's suggestion may work, the proper way to do this is as rindi said.

Open computer management from the administrative tools or run compmgmt.msc from an administrative command prompt and expand Local Users and Groups under System Tools.  Click on Groups and then in the middle pane with the list of groups, open Remote Desktop Users and add the account you want to log in with to that group.  It SHOULD allow you to connect without a log off / on or reboot.

See graphic below.RD Users in Computer Management
0
Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

 

Author Comment

by:Gelly77
ID: 40470329
I have tested a few different solutions:
1. Added username to Remote Desktop Group - did not work
2. Added username to Allow log on through Remote Desktop Services in local security policy - did not work
3. Remove Everyone group from Deny log on through Remote Desktop Services in local security polity- worked but this cannot be used as it leaves RDP open to everyone.

Any Suggestions?
0
 
LVL 96

Assisted Solution

by:Lee W, MVP
Lee W, MVP earned 334 total points
ID: 40470738
The DEFAULT setting lists NO ONE / NO GROUP in Deny log on through Remote Desktop Services
Why did you change this?

Windows permissions are MOST RESTRICTIVE.  And they do NOT permit something if not EXPLICITLY granted.  It sounds like you broke this yourself when you (or someone) added the everyone group to the Deny log on through Remote Desktop Services.

Fix that.  Then grant only those you want to have access.  Post SCREEN SHOTS of errors before you make additional changes (once this has been done).
0
 

Accepted Solution

by:
Gelly77 earned 0 total points
ID: 40546492
I had to remove the everyone and the administrators group from the deny logon through remote desktop services. All is working now!!!!
0
 

Author Closing Comment

by:Gelly77
ID: 40556015
My solution resolved the issue. The comments from the other submitters assisted me in getting to the solution.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Understanding the various editions available is vital when you decide to purchase Windows Server 2012. You need to have a basic understanding of the features and limitations in each edition in order to make a well-informed decision that best suits y…
The reason that corporations and businesses use Windows servers is because it supports custom modifications to adapt to the business and what it needs. Most individual users won’t need such powerful options. Here I’ll explain how you can enable Wind…
In this Micro Tutorial viewers will learn how to restore their server from Bare Metal Backup image created with Windows Server Backup feature. As an example Windows 2012R2 is used.
This tutorial will walk an individual through the process of installing of Data Protection Manager on a server running Windows Server 2012 R2, including the prerequisites. Microsoft .Net 3.5 is required. To install this feature, go to Server Manager…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question