Re: Log on Interactively



The server is a Windows 2003 Enterprise Edition Server
It is a member server.

It appears that the permissions on the rdp-tcp connection was the problem.
I added the Remote Desktop Users group to the permissions tab with the User
Access rights. I then added the Terminal Services User group that I had
created as member of this Remote Desktop Users group. The login appears to
be working now.

I do have another question though...what is the purpose of the check box
called "Allow logon to terminal server on the Terminal Services Profile tab
of the user's properties if you have to assign them to the group anyway?

Thanks,

Brett Gibson
Gibson Teldata, Inc.

"Vera Noest [MVP]" wrote:

> Is the TS running W2K or 2003?
> Is the TS also a Domain Controller, or a member server?
> What are the permissions on the rdp-tcp connection?
>
> --
> Vera Noest
> MCSE, CCEA, Microsoft MVP - Terminal Server
> http://hem.fyristorg.com/vera/IT
> --- please respond in newsgroup, NOT by private email ---
>
> =?Utf-8?B?QnJldHQgR2lic29u?=
> <BrettGibson@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote on 18 maj 2005 in
> microsoft.public.windows.terminal_services:
>
> > I am having problems with getting a user to be able to login to
> > Terminal Services.
> >
> > The error that I am getting is:
> >
> > -----------
> >
> > Logon Message
> >
> > The local policy of this system does not permit you to logon
> > interactively.
> >
> > ------------
> >
> > I have created a security group called Terminal Services User
> > and added the user as member of the group.
> >
> > I have created a Group Policy and assigned the Terminal Services
> > User to the scope. I also have the Terminal Services machine
> > assigned to an OU called Terminal Servers that are also assigned
> > to the scope. There are no other Group Policies overriding
> > these.
> >
> > Here is what I have assigned to the Group Policy so far:
> >
> > Windows Settings
> > Security Settings
> > Local Policies/User Rights Assignment
> > Policy Setting
> > Allow log on locally BGIBSONCOM\Terminal Services User,
> > BUILTIN\Administrators
> >
> > Local Policies/Security Options
> > Devices
> > Policy Setting
> > Devices: Restrict CD-ROM access to locally logged-on user only
> > Enabled Devices: Restrict floppy access to locally logged-on
> > user only Enabled
> >
> > Interactive Logon
> > Policy Setting
> > Interactive logon: Do not display last user name Enabled
> >
> > System Services
> > Help and Support (Startup Mode: Disabled)
> > Permissions
> > No permissions specifiedAuditing
> > No auditing specified
> > Administrative Templates
> > Windows Components/Terminal Services
> > Policy Setting
> > Restrict Terminal Services users to a single remote session
> > Enabled
> >
> > Windows Components/Windows Installer
> > Policy Setting
> > Disable Windows Installer Enabled
> > Disable Windows Installer Always
> >
> >
> > User Configuration (Enabled)
> > No settings defined.
> >
> > Brett Gibson
> > Gibson Teldata, Inc.
>
.



Relevant Pages

  • RE: SBS 2003 Outoging Fax Problem w/Error 32028 (Cannot send - fatal error)
    ... 1.Reduce the baud rate of the incoming fax modem and see how it goes. ... Click Permissions and verify that the user attempting to fax has at ... 3.If you have configured the fax client on the Windows XP computer ... On the "Additional Server Types" page, ...
    (microsoft.public.windows.server.sbs)
  • Re: Please Help!
    ... Windows 2000 Terminal Services Licensing FAQ ... Q. What licenses are required to run Terminal Services in Windows ... required to run applications on a Windows 2000 Server via Terminal ...
    (microsoft.public.win2000.termserv.apps)
  • RE: Userenv Error
    ... Microsoft Windows Small Business Server 2003 Service Pack 1 ... Please check both the Share Permissions of the Group folder, ...
    (microsoft.public.windows.server.sbs)
  • Re: Workgroup server to domain
    ... Microsoft MVP - Windows NT Server ... >>may have to add permissions for domain users to access ... >>Scott Harding ... >>Microsoft MVP - Windows NT Server ...
    (microsoft.public.windows.server.migration)
  • Re: login/logoff Report
    ... located both the cmd files in the correct place now. ... Make sure you have hotfix 842933 applied to the SBS server ... truncated" error message when you try to modify or to view GPOs in Windows ... Make sure the "logging folder" share has Share Permissions: ...
    (microsoft.public.windows.server.sbs)