The user account is not authorized for remote login and all policies are in place.


hi guys,

ive got strange problem , second time ive encountered this.

the thing cant connect server rdp client. gives me warning user account not authorized remote login.

client:workstation windows 7 64 bit , server: windows 2012 r2

im using following group policy enable local admin rights , rdp rights:

policies\windows\settings\security settings\local policies/user rights assignment

allow log on through terminal services
xxxx\g-bp-localserveradmin-remotedesktop, xxxx\domain admins, xxxx\administrator


restricted groups

group members  member of
xxxx\g-bp-localserveradmin-remotedesktop  builtin\remote desktop users, builtin\administrators


administrative templates\network/network connections/windows firewall/domain profile
windows firewall: allow inbound remote desktop exceptions           enabled 


windows components/remote desktop services/remote desktop session host/connections
allow users connect remotely using remote desktop services       enabled 

windows components/remote desktop services/remote desktop session host/security
not allow local administrators customize permissions               enabled 
require user authentication remote connections using network level authentication            enabled

the weird thing account error. other account working fine. same group rights etc,

with account on other servers functions fine same policy (copy different servers).

when in server , @ properties stated user has access. im member of "g-bp-localserveradmin-remotedesktop" group , can login localy on server (via console access).

when add account directly in administrators group or in remote desktop users group i can login rdp.

does has idea coming from? don't want add users directly groups.

greets vincent

hi vincent,

is server domain controller or domain member server?

please run gpresult.exe on server clear view allow log on through terminal services setting, since not gpo settings applied due precedence , security filtering.

please note if have modified policy setting allow log on through terminal service, we need add both administrators , remote desktop users groups avoid unintended results.

here related blog below should useful you:

“allow logon through terminal services” group policy , “remote desktop users” group
http://blogs.technet.com/b/askperf/archive/2011/09/09/allow-logon-through-terminal-services-group-policy-and-remote-desktop-users-group.aspx
 
best regards,
amy


please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Windows Server 2012 General



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2