Re: Remote Desktop Logon to Server

From: Chaplain Doug (anonymous_at_discussions.microsoft.com)
Date: 09/23/04


Date: Thu, 23 Sep 2004 06:52:26 -0700

Don't know why I chose the word "administrative." Indeed
an apparent contradiction. What I want to do is allow a
person to logon to the server in a restricted mode. I DO
NOT want them to have administrative capabilities.

At present the only way I have been able to make their
remote logon work is to make them a member of the
Administrators group. This is not what I wanted to do. I
want their logon to the server to be a restricted logon
(not super user or administrator). How do I accomplish
this?

I tried placing their user name in the local security
settings-local policies-user rights assignment-log on
locally, but they were still unable to log on after the
change (this was before I put them into the Administrator
group). What else could I try?

>-----Original Message-----
>First, it sounds like you have login restrictions on your
server, either
>from Active Directory or from the local Machine
Policies. You need to
>change whichever is in force to allow other than
Administrator users to log
>in.
>
>Your second request is a contradiction in terms. To
allow someone
>"administrative" access to a server allows them full
access.
>
>--
>Richard G. Harper [MVP Win9x] rgharper@email.com
>* PLEASE post all messages and replies in the newsgroups
>* for the benefit of all. Private mail is usually not
replied to.
>* My website, such as it is ... http://rgharper.mvps.org/
>* HELP us help YOU ... http://www.dts-l.org/goodpost.htm
>
>
>"Chaplain Doug" <anonymous@discussions.microsoft.com>
wrote in message
>news:0f0a01c4a0db$cf5c2120$a401280a@phx.gbl...
>> Windows 2000 Server. I want to allow a remote user to
>> logon to my server (via remote desktop) for some limited
>> work. At present, when they try to logon the server
>> says, "The local policy of this system does not permit
you
>> to logon interactively."
>>
>> First, what must I change to allow this user to logon to
>> my server remotely via remote desktop?
>>
>> Second, how can I restrict the user's activities so that
>> they are only able to do administrative things on the
>> server?
>>
>> Thanks.
>
>
>.
>



Relevant Pages

  • Re: Please help refresh my memory on AD DC
    ... When I boot my Laptop I reach the Logon screeen for XP Laptop and here I am ... administrator account. ... account to be able to Login so I can control it from the DC. ... A Server has websites already hosted on it in a Workgroup and now I join it ...
    (microsoft.public.windows.server.active_directory)
  • Re: Constrained delegation question!
    ... The event logs we need to know about are the ones on the server running the services you are controlling remotely. ... Can you show what happens when you have a console app that accesses the remote server running the services in terms of the security audits on the ... AUTHORITY\ANONYMOUS LOGON event. ... you won't be able to get Kerb delegation to ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • RE: HELP!!!!
    ... Please feel free to post back when you need further assistance on the logon ... All is OK now with the exception that Remote Access ... >> server locally after you setup Remote Access. ... >> member of either the Remote Operators group or the Domain Power Users ...
    (microsoft.public.windows.server.sbs)
  • Re: Please help refresh my memory on AD DC
    ... "WEB308\administrator" does not longer exist, because DC's have no local administrator. ... The computer is now member of the domain, if you mean this and still has the local user account. ... "in order to add the server or pc I would have to have a user on the domain to logon to the domain. ... To Logon locally I would use the admin account of the Server 2003 machine. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Just administrator can access TS
    ... members of the Remote Desktop ... Event Source: Security ... Special privileges assigned to new logon: ... Microsoft MVP - Terminal Server ...
    (microsoft.public.windows.terminal_services)