allow remote desktop to specific users gpo


hi..

i want allow connections computers running remote desktop network level authentication (more secure) , add specific user group (it-group) users list gpo

this moves i've made in ad :

1- computer configuration\policies\administrative templates\windows components\remote desktop services\remote desktop session host\connections\allow users connect remotely using remote desktop services = enabled

2- computer configuration\policies\administrative templates\windows components\remote desktop services\remote desktop session host\security\require user authentication remote connections using network level authentication = enable

3- computer configuration\policies\windows sittings\security setting\windows firewall advanced security\inbound rules\remote desktop = allowed

4- computer configuration\policies\windows sittings\security setting\local policies\user right assignment\access computer network = enable (it-group)

5- computer configuration\policies\windows sittings\security setting\local policies\user right assignment\allow log on through remote desktop services = enable (it-group)

6- grope member of domain users group , read-only domain controllers , remote desktop users

but massage when try connect user in it-group:

"the connection denied because user account not authorized remote login"

how make group (it-group) authorize remote login




hi.

is server configured remote desktop services (terminal server) or type of server?
add it-group either remote desktop user localy on server or local administrator group on depending on rights need.
can achive using restricted groups in group policy. found under computer configuration - windows settings - restricted groups.
remember add right way. group member of builtin\adminstrators group.

 


ohm http://msitpros.com


Windows Server  >  Remote Desktop Services (Terminal Services)



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2