Click here to get back home

USER AND TERMINAL SERVER

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
USER AND TERMINAL SERVER JP 07-03-2007
Posted by Al Dunbar on July 5, 2007, 9:04 am
Please log in for more thread options
Can you open a remote desktop session using an account having local
administrator rights on the server? Can the user in question logon directly
at the server? It could be that one needs logonAtServer privilege in
addition to remote desktop privileges. Or alternately, could there be some
policy in place that denies him access?

/Al

> He is attempting to connect to 2003 Server thru Terminal Server from a XP
> desktop, and he is memnber of "remote desktop users" group on the server.
> Thanks.
>
>
>
>> Which group did you at the user to, the "remote desktop users" group on
> the
>> server, in the domain, or on the workstation from which the user is
>> attempting to open an RDP session on?
>>
>> /Al
>>
>> > Yes, I added to that group, and It does not work.
>> >
>> >
>> >> Are you saying that you added the user to the group named "Remote
> Desktop
>> >> Users?" That's the group that Windows creates by default and should
> work.
>> >>
>> >> Hi! I have a user on a 2003 Server wich is member of group "users". I
>> >> made
>> >> this user member os group "users of remote desktop" to allow this user
> to
>> >> logon from terminal server, but when I try it, appears a window
>> >> telling
> I
>> >> can't login because I have no permission. What can I do?. Thanks.
>> >>
>> >>
>> >>
>> >
>> >
>>
>>
>
>



Posted by JP on July 10, 2007, 3:28 am
Please log in for more thread options
Yes, with the user "administrator" I can open a remote desktop session, and
if I add the user that can not logon
thru terminal server to the administrators group, he can access thru
terminal server. Thanks.



> Can you open a remote desktop session using an account having local
> administrator rights on the server? Can the user in question logon
directly
> at the server? It could be that one needs logonAtServer privilege in
> addition to remote desktop privileges. Or alternately, could there be some
> policy in place that denies him access?
>
> /Al
>
> > He is attempting to connect to 2003 Server thru Terminal Server from a
XP
> > desktop, and he is memnber of "remote desktop users" group on the
server.
> > Thanks.
> >
> >
> >
> >> Which group did you at the user to, the "remote desktop users" group on
> > the
> >> server, in the domain, or on the workstation from which the user is
> >> attempting to open an RDP session on?
> >>
> >> /Al
> >>
> >> > Yes, I added to that group, and It does not work.
> >> >
> >> >
> >> >> Are you saying that you added the user to the group named "Remote
> > Desktop
> >> >> Users?" That's the group that Windows creates by default and should
> > work.
> >> >>
> >> >> Hi! I have a user on a 2003 Server wich is member of group "users".
I
> >> >> made
> >> >> this user member os group "users of remote desktop" to allow this
user
> > to
> >> >> logon from terminal server, but when I try it, appears a window
> >> >> telling
> > I
> >> >> can't login because I have no permission. What can I do?. Thanks.
> >> >>
> >> >>
> >> >>
> >> >
> >> >
> >>
> >>
> >
> >
>
>



Posted by Al Dunbar on July 10, 2007, 9:32 pm
Please log in for more thread options
I'll ask you again: can the user in question logon to the actual, physical
server in question. directly, not through remote desktop? If he cannot, then
you should provide, not full administrator access, but just "logon at
server" in addition to making him a "remote desktop user".

/Al

> Yes, with the user "administrator" I can open a remote desktop session,
> and
> if I add the user that can not logon
> thru terminal server to the administrators group, he can access thru
> terminal server. Thanks.
>
>
>
>> Can you open a remote desktop session using an account having local
>> administrator rights on the server? Can the user in question logon
> directly
>> at the server? It could be that one needs logonAtServer privilege in
>> addition to remote desktop privileges. Or alternately, could there be
>> some
>> policy in place that denies him access?
>>
>> /Al
>>
>> > He is attempting to connect to 2003 Server thru Terminal Server from a
> XP
>> > desktop, and he is memnber of "remote desktop users" group on the
> server.
>> > Thanks.
>> >
>> >
>> >
>> >> Which group did you at the user to, the "remote desktop users" group
>> >> on
>> > the
>> >> server, in the domain, or on the workstation from which the user is
>> >> attempting to open an RDP session on?
>> >>
>> >> /Al
>> >>
>> >> > Yes, I added to that group, and It does not work.
>> >> >
>> >> >
>> >> >> Are you saying that you added the user to the group named "Remote
>> > Desktop
>> >> >> Users?" That's the group that Windows creates by default and should
>> > work.
>> >> >>
>> >> >> Hi! I have a user on a 2003 Server wich is member of group "users".
> I
>> >> >> made
>> >> >> this user member os group "users of remote desktop" to allow this
> user
>> > to
>> >> >> logon from terminal server, but when I try it, appears a window
>> >> >> telling
>> > I
>> >> >> can't login because I have no permission. What can I do?. Thanks.
>> >> >>
>> >> >>
>> >> >>
>> >> >
>> >> >
>> >>
>> >>
>> >
>> >
>>
>>
>
>



Posted by JP on July 11, 2007, 5:42 am
Please log in for more thread options
OK, where can I to config "logon at server" for the user, adding it to an OU
or how?. Thanks a lot.



> I'll ask you again: can the user in question logon to the actual, physical
> server in question. directly, not through remote desktop? If he cannot,
then
> you should provide, not full administrator access, but just "logon at
> server" in addition to making him a "remote desktop user".
>
> /Al
>
> > Yes, with the user "administrator" I can open a remote desktop session,
> > and
> > if I add the user that can not logon
> > thru terminal server to the administrators group, he can access thru
> > terminal server. Thanks.
> >
> >
> >
> >> Can you open a remote desktop session using an account having local
> >> administrator rights on the server? Can the user in question logon
> > directly
> >> at the server? It could be that one needs logonAtServer privilege in
> >> addition to remote desktop privileges. Or alternately, could there be
> >> some
> >> policy in place that denies him access?
> >>
> >> /Al
> >>
> >> > He is attempting to connect to 2003 Server thru Terminal Server from
a
> > XP
> >> > desktop, and he is memnber of "remote desktop users" group on the
> > server.
> >> > Thanks.
> >> >
> >> >
> >> >
> >> >> Which group did you at the user to, the "remote desktop users" group
> >> >> on
> >> > the
> >> >> server, in the domain, or on the workstation from which the user is
> >> >> attempting to open an RDP session on?
> >> >>
> >> >> /Al
> >> >>
> >> >> > Yes, I added to that group, and It does not work.
> >> >> >
> >> >> >
> >> >> >> Are you saying that you added the user to the group named "Remote
> >> > Desktop
> >> >> >> Users?" That's the group that Windows creates by default and
should
> >> > work.
> >> >> >>
> >> >> >> Hi! I have a user on a 2003 Server wich is member of group
"users".
> > I
> >> >> >> made
> >> >> >> this user member os group "users of remote desktop" to allow this
> > user
> >> > to
> >> >> >> logon from terminal server, but when I try it, appears a window
> >> >> >> telling
> >> > I
> >> >> >> can't login because I have no permission. What can I do?. Thanks.
> >> >> >>
> >> >> >>
> >> >> >>
> >> >> >
> >> >> >
> >> >>
> >> >>
> >> >
> >> >
> >>
> >>
> >
> >
>
>



Posted by Jason Rivers on July 13, 2007, 8:01 am
Please log in for more thread options
I'm having a similar issue,

We have a Terminal Services system: the system is headless and sits in a
server rack, the machine was fine, allowed users to log on, this is for VPN
users to have a desktop in the office. the system is running Windows server
2003 R2 SP2, it has just been set to be a MEMBER of our domain, so that
users don't have to change their passwords in multiple places, and now the
users can not log in, I get the message saying "to log on to this computer,
you must be granted the allow log on through terminal services....." the
user is a member of "Remote Desktop Users" on the domain controller, if I
set the user into the "administrators" group, they still can't log on, but
if I change to "Domain Admins" then they can. this is a problem as it is a
terminal system, there is no physical access to the system.

I also don't know how to set "logon at server" for the user, and will this
still work given the server is not a domain controller but a member of the
domain?

/J

> OK, where can I to config "logon at server" for the user, adding it to an
> OU
> or how?. Thanks a lot.
>
>
>
>> I'll ask you again: can the user in question logon to the actual,
>> physical
>> server in question. directly, not through remote desktop? If he cannot,
> then
>> you should provide, not full administrator access, but just "logon at
>> server" in addition to making him a "remote desktop user".
>>
>> /Al
>>
>> > Yes, with the user "administrator" I can open a remote desktop session,
>> > and
>> > if I add the user that can not logon
>> > thru terminal server to the administrators group, he can access thru
>> > terminal server. Thanks.
>> >
>> >
>> >
>> >> Can you open a remote desktop session using an account having local
>> >> administrator rights on the server? Can the user in question logon
>> > directly
>> >> at the server? It could be that one needs logonAtServer privilege in
>> >> addition to remote desktop privileges. Or alternately, could there be
>> >> some
>> >> policy in place that denies him access?
>> >>
>> >> /Al
>> >>
>> >> > He is attempting to connect to 2003 Server thru Terminal Server from
> a
>> > XP
>> >> > desktop, and he is memnber of "remote desktop users" group on the
>> > server.
>> >> > Thanks.
>> >> >
>> >> >
>> >> >
>> >> >> Which group did you at the user to, the "remote desktop users"
>> >> >> group
>> >> >> on
>> >> > the
>> >> >> server, in the domain, or on the workstation from which the user is
>> >> >> attempting to open an RDP session on?
>> >> >>
>> >> >> /Al
>> >> >>
>> >> >> > Yes, I added to that group, and It does not work.
>> >> >> >
>> >> >> >
>> >> >> >> Are you saying that you added the user to the group named
>> >> >> >> "Remote
>> >> > Desktop
>> >> >> >> Users?" That's the group that Windows creates by default and
> should
>> >> > work.
>> >> >> >>
>> >> >> >> Hi! I have a user on a 2003 Server wich is member of group
> "users".
>> > I
>> >> >> >> made
>> >> >> >> this user member os group "users of remote desktop" to allow
>> >> >> >> this
>> > user
>> >> > to
>> >> >> >> logon from terminal server, but when I try it, appears a window
>> >> >> >> telling
>> >> > I
>> >> >> >> can't login because I have no permission. What can I do?.
>> >> >> >> Thanks.
>> >> >> >>
>> >> >> >>
>> >> >> >>
>> >> >> >
>> >> >> >
>> >> >>
>> >> >>
>> >> >
>> >> >
>> >>
>> >>
>> >
>> >
>>
>>
>
>


Similar ThreadsPosted
terminal server client question September 9, 2005, 5:52 pm
Sharing a Local Printer in Terminal Server December 5, 2006, 2:50 pm
Sharing a Local Printer in Terminal Server December 5, 2006, 2:50 pm
Execute access to files from Terminal server August 3, 2007, 2:17 pm
audit logon/logoff events on terminal server July 18, 2007, 10:29 am
Logon/Logoff Events in Local Security Log of Terminal Server July 20, 2007, 2:39 pm
Security bug in terminal services? May 4, 2006, 4:02 am
terminal service connection September 14, 2006, 6:08 am
Logon Using Terminal Services GPO August 16, 2007, 2:57 am
Terminal Services Profiles problems August 15, 2005, 5:08 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap