WIN2K AD issue with Terminal Server 2003

From: Zoroaster (Zoroaster_at_discussions.microsoft.com)
Date: 08/06/04


Date: Fri, 6 Aug 2004 09:55:02 -0700

I added a Win2003 Terminal server to our Win2K AD network.

>From within AD user profiles you can check a box that allows the user
permission to connect to a terminal server on the network.

>From within Win Server 2003 I setup terminal services. I selected settings
to allow users to logon using Standard Windows Authentication and USING
CLIENT PROVIDED LOGON settings. The issue is that the user cannot log into
the server through the domain receiving the error they are not allowed to
login ineteractively.

The only way they are allowed to logon is when I add them to the Remote
Desktop Users group by username and not by group object. This allows them to
logon through the domain and not locally.

Still I don't understand why I have to add them locally to the box when
their user profile in Active Directory is given permission to log into a
terminal server.

Seems pointless to have that terminal services setting under the user
profile from within AD if it doesn't allow you login.



Relevant Pages

  • Re: Terminal Server and Local Policy
    ... It is not a question of "user profiles" (you can have those on Windows 98 ... A Terminal Server can not "override" client ... icon to connect to the Terminal Server, they can not logon to the Terminal ... "Remote Desktop Users" group have the right to logon via Terminal Services. ...
    (microsoft.public.windows.server.general)
  • Re: Terminal Server User Setup
    ... if you have published terminal services to internet. ... >> I already setup the Terminal Server and all users can connect to TS ... users can logon to domain through VPN and then ...
    (microsoft.public.windows.server.sbs)
  • Re: TS Logon Restriction by hours
    ... prevent the user's home computers from connecting to the Terminal Server ... 'Logon Hours' restrictions for a domain account (as these would ... prevent the account from logging into the network at all during this ...
    (microsoft.public.windows.terminal_services)
  • Re: Domain Users cant execute applications on SBServer
    ... execute the program on the Terminal Server. ... the domain user logon workstation have administrator permission ... Add the domain users group to Terminal Server local Administrators group: ...
    (microsoft.public.windows.server.sbs)
  • Re: IISRESET needed for clients to reestablish TS-connection
    ... I hope this might have been the login failures on our TS through TS Gateway. ... This event is generated when a logon session is destroyed. ... Our clients are able to reconnect to the Terminal Server after this ...
    (microsoft.public.windows.terminal_services)

Loading