Re: Termserv loses security settings each night



Windows server 2003 standard edition service pack 1
It is a member server in a single-domain forest.
Domain Security Policy might be the key - see below.

The error is
"To logon to this remote computer, you must be granted the allow to log
on through terminal services right. By default, members of the Remote
Dektop Users group have this right. If you are not a member of the
Remote Desktop Users group or another group that has this right, or if
the remote dekstop users group does not have this right, you must be
granted the right manually."

Now that I enabled more auditing, I also receive this event log error:
Logon Failure:
Reason: The user has not been granted the requested
logon type at this machine
User Name: tsuser1
Domain: domainname
Logon Type: 10
Logon Process: User32
Authentication Package: Negotiate
Workstation Name: TS1
Caller User Name: TS1$
Caller Domain: domainname
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 2432
Transited Services: -
Source Network Address: 67.71.89.117
Source Port: 1348
---
This morning, same problem. I got it working today by adding a GPO
that defines local policy for Allow to Logion to Terminal Services and
includes my TSUsers global group. It's working again - just like
yesterday and the day before. In fact, I can prove the GPO controls it
by adding/removing the policy and seeing it work/fail.

But I don't feel confident about this fix, because it is essentially
what I used before - I had already added both tsusers and remote
desktop users into a doamin-wide GPO earlier. That worked but only
temporarily. There's no inheritance blocking and or No Overrides in
effect that would explain why this is working.

I think the problem might lie somewhere in the GPOs but it doesn't
explain why it would break in the middle of the night, or why it would
break at all once it was functioning.

I initially setup security by putting the users into a TSUsers global
group, and placing the TSusers global group into the Remote Desktop
Users group on the termserver. When this failed (after working for a
month), I went into Terminal Services Configuration, Connections,
RDP-Tcp - properties. I added permissions to allow the global group
access (user access and guest access.) when that failed the next day,
I used a different global group that the users are a member of. I
don't remember the exact sequence, but I also have a domain level GPO
that defines local policy for terminal services access, and now today I
have a GPO for my termserv container.
I have been making changes in those places each day to get the users
back online.

The time frame for the initial failure was when it installed security
patch KB912919.

.



Relevant Pages

  • Re: Locked out of Win2k Server
    ... >> When you joined the rebuilt machine to the domain it was>> subjected to the Group Policy GPO's of the domain. ... Those GPO settings were still in effect ready to>> configure the machine once it was joined. ... >>>> That you cannot log into the member server with either ...
    (microsoft.public.windows.server.security)
  • Re: Exchange OWA 2003 Trusted Root Certificate
    ... > So you're going to explain to me how Group Policy works now? ... When I say Policy, I mean it in a broad sense, I am referring to the GPO, ... which as you admitted defaults to "apply" to the Authenticated Users. ... > One cannot be a member of a GPO. ...
    (microsoft.public.win2000.security)
  • Re: Group Policy Across Sites
    ... The GPO is applied at the domain level. ... >>I am trying to apply a group policy that alters the IE proxy settings. ... >> here at the main office but not at my primary remote site. ...
    (microsoft.public.windows.group_policy)
  • Re: policy confusement
    ... domain policy is loaded. ... There are two components to every GPO - Computer settings and User ... OUs and policies I would strongly suggest ... > The only OU member in the DC OU is the machine that has run dcpromo. ...
    (microsoft.public.win2000.networking)
  • Re: Group Policy Across Sites
    ... >I am trying to apply a group policy that alters the IE proxy settings. ... > here at the main office but not at my primary remote site. ... The remote server is a controller and a GC, ... Where are you linking the GPO? ...
    (microsoft.public.windows.group_policy)