Log on Interactively



I am having problems with getting a user to be able to login to Terminal
Services.

The error that I am getting is:

-----------

Logon Message

The local policy of this system does not permit you to logon interactively.

------------

I have created a security group called Terminal Services User and added the
user as member of the group.

I have created a Group Policy and assigned the Terminal Services User to the
scope. I also have the Terminal Services machine assigned to an OU called
Terminal Servers that are also assigned to the scope. There are no other
Group Policies overriding these.

Here is what I have assigned to the Group Policy so far:

Windows Settings
Security Settings
Local Policies/User Rights Assignment
Policy Setting
Allow log on locally BGIBSONCOM\Terminal Services User,
BUILTIN\Administrators

Local Policies/Security Options
Devices
Policy Setting
Devices: Restrict CD-ROM access to locally logged-on user only Enabled
Devices: Restrict floppy access to locally logged-on user only Enabled

Interactive Logon
Policy Setting
Interactive logon: Do not display last user name Enabled

System Services
Help and Support (Startup Mode: Disabled)
Permissions
No permissions specifiedAuditing
No auditing specified
Administrative Templates
Windows Components/Terminal Services
Policy Setting
Restrict Terminal Services users to a single remote session Enabled

Windows Components/Windows Installer
Policy Setting
Disable Windows Installer Enabled
Disable Windows Installer Always


User Configuration (Enabled)
No settings defined.

Brett Gibson
Gibson Teldata, Inc.

.



Relevant Pages

  • Re: Log on Interactively
    ... > I have created a security group called Terminal Services User ... > Local Policies/User Rights Assignment ... > Policy Setting ... > Disable Windows Installer Enabled ...
    (microsoft.public.windows.terminal_services)
  • Re: No Shut Down or Restart for Domain Admins
    ... I have created a group policy in a development network and imported it ... NT AUTHORITY\Authenticated Users Read (from Security Filtering) No ... Enforce user logon restrictions Enabled ... Policy Setting ...
    (microsoft.public.windows.server.active_directory)
  • No Shut Down or Restart for Domain Admins
    ... I have created a group policy in a development network and imported it into ... NT AUTHORITY\Authenticated Users Read (from Security Filtering) No ... Policy Setting ... Enforce user logon restrictions Enabled ...
    (microsoft.public.windows.server.active_directory)
  • RE: 802.1x logon sripts and roaming profile not running
    ... Ran into this problem when deploying 802.1x on wired network. ... too fast and network authentication was not actually occurring until after ... logon. ... Policy Setting ...
    (microsoft.public.windows.group_policy)
  • Effective Policy Setting for IWAM_Machinename account
    ... I receive this error message every so often when trying to run a ISAPI ... DCOM got error "Logon failure: the user has not been granted the requested ... How do I make the Effective Policy Setting selected? ...
    (microsoft.public.win2000.security)

Loading