The user account is not authorized for remote login and all policies are in place.
hi guys,
ive got strange problem , second time ive encountered this.
the thing cant connect server rdp client. gives me warning user account not authorized remote login.
client:workstation windows 7 64 bit , server: windows 2012 r2
im using following group policy enable local admin rights , rdp rights:
policies\windows\settings\security settings\local policies/user rights assignment
allow log on through terminal services
xxxx\g-bp-localserveradmin-remotedesktop, xxxx\domain admins, xxxx\administrator
restricted groups
group members member of
xxxx\g-bp-localserveradmin-remotedesktop builtin\remote desktop users, builtin\administrators
administrative templates\network/network connections/windows firewall/domain profile
windows firewall: allow inbound remote desktop exceptions enabled
windows components/remote desktop services/remote desktop session host/connections
allow users connect remotely using remote desktop services enabled
windows components/remote desktop services/remote desktop session host/security
not allow local administrators customize permissions enabled
require user authentication remote connections using network level authentication enabled
the weird thing account error. other account working fine. same group rights etc,
with account on other servers functions fine same policy (copy different servers).
when in server , @ properties stated user has access. im member of "g-bp-localserveradmin-remotedesktop" group , can login localy on server (via console access).
when add account directly in administrators group or in remote desktop users group i can login rdp.
does has idea coming from? don't want add users directly groups.
greets vincent
hi vincent,
is server domain controller or domain member server?
please run gpresult.exe on server clear view allow log on through terminal services setting, since not gpo settings applied due precedence , security filtering.
please note if have modified policy setting allow log on through terminal service, we need add both administrators , remote desktop users groups avoid unintended results.
here related blog below should useful you:
“allow logon through terminal services” group policy , “remote desktop users” group
http://blogs.technet.com/b/askperf/archive/2011/09/09/allow-logon-through-terminal-services-group-policy-and-remote-desktop-users-group.aspx
best regards,
amy
please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.
Windows Server > Windows Server 2012 General
Comments
Post a Comment