allow remote desktop to specific users gpo
hi..
i want allow connections computers running remote desktop network level authentication (more secure) , add specific user group (it-group) users list gpo
this moves i've made in ad :
1- computer configuration\policies\administrative templates\windows components\remote desktop services\remote desktop session host\connections\allow users connect remotely using remote desktop services = enabled
2- computer configuration\policies\administrative templates\windows components\remote desktop services\remote desktop session host\security\require user authentication remote connections using network level authentication = enable
3- computer configuration\policies\windows sittings\security setting\windows firewall advanced security\inbound rules\remote desktop = allowed
4- computer configuration\policies\windows sittings\security setting\local policies\user right assignment\access computer network = enable (it-group)
5- computer configuration\policies\windows sittings\security setting\local policies\user right assignment\allow log on through remote desktop services = enable (it-group)
6- grope member of domain users group , read-only domain controllers , remote desktop users
but massage when try connect user in it-group:
"the connection denied because user account not authorized remote login"
how make group (it-group) authorize remote login
hi.
is server configured remote desktop services (terminal server) or type of server?
add it-group either remote desktop user localy on server or local administrator group on depending on rights need.
can achive using restricted groups in group policy. found under computer configuration - windows settings - restricted groups.
remember add right way. group member of builtin\adminstrators group.
ohm http://msitpros.com
Windows Server > Remote Desktop Services (Terminal Services)
Comments
Post a Comment