RDP onto DCs with non-admin accounts



I'm having some fun and games getting non-admin accounts to be able to RDP
onto my DCs. Scenario as follows:

Windows Server 2003 forest, raised to 2003 functional level.

User is using a secondary logon account, which is a member of
"Builtin\Remote Desktop Users" and has the User Right "Log on locally"
assigned via the "Default Domain Controllers Policy"

Ordinarily this works fine (well it does in both my test forests) but in the
Production Forest there are 4 DCs which won't accept the logon.

I've checked and all policies are in synch (checked using GPOTOOL across
Sysvol and the AD) and DCDIAG reports no problems. Nothing useful is
appearing in the event log.

When the user is denied logon to my errant DCs he gets "The local policy of
the sysem won't allow you to logon interactively"; however this user account
can connect via the iLO board and logon to the console so they clearly can!

The RDP permissions are set to normal, ie "Builtin\RemoteDesktopUsers" have
User and Guest access.

I'm clearly missing something but I don't know what! Any guidance would be
gratefully received.
.



Relevant Pages

  • RE: the local policy of this system does not permit you to logon inter
    ... Add there the Users you want to logon at the DCs and make sure that they are ... not denied the local log on in "Deny logon locally" ... Usually you should be able to login with the "Administrator" account you ...
    (microsoft.public.windows.group_policy)
  • Re: single logon
    ... > Please give me an idea how to config an account to have a single logon ... when the user logs onto a domain account ... In a Win2000+ Forest the trusts ... Permissions though are required and may either grant ...
    (microsoft.public.win2000.active_directory)
  • RAS with two domains?
    ... 2000 and 2003 in the same forest and one RAS/IAS server. ... I can only logon when I use an account from the domain where RAS and IAS are ...
    (microsoft.public.windows.server.networking)
  • [EC-SA-01.2003] Windows XP "welcome screen" exposes the names of all the members of the l
    ... logon screen with what is called "Welcome Screen". ... (including the original administrator account, ... Using the "welcome screen" actually disables / ignores the security ...
    (Bugtraq)
  • Re: ATTN : Microsoft - Security Event 529....Second Request for help....
    ... According to the events, the logon ... failure is from the local machine account. ... disconnected from the network. ... Security Event ID 529 is a failure audit for logon/logoff. ...
    (microsoft.public.windows.server.sbs)