Re: allow logon through terminal services



We have a mixture of 2000 and 2003 servers. I was wondering about using net
localgroup add would work using psexec to add the user as a local
administrator to each machine.


"Patrick Rouse" <PatrickRouse@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:CBB430F5-915F-4A8E-A97C-74B1AD90A814@xxxxxxxxxxxxxxxx
> Add his domain account to the local Remote Desktop Users Group, or create
> a
> new Domain Security Group, add his accoun to that and add that group to
> the
> local Remote Desktop Users Group.
>
> Dy Default Domain Admins is a member of the local Administrators group
> which
> has permissions to the RDP-Tcp connection (by default).
>
> I assume that you're running 2003, since 2000 requires the logon locally
> right.
>
> http://www.workthin.com/tshta.htm
>
> --
> Patrick Rouse
> Microsoft MVP - Terminal Server
> http://www.workthin.com
>
>
> "Shayne D. Swann" wrote:
>
>> I have a Telecom user (a switch guy) that needs to to be able to logon to
>> all of our servers through terminal services. We have recently removed
>> all
>> non-server administrators from the domain administrators group. THis user
>> was one of the members of the domain admins group. I want to grant him
>> the
>> right to logon to the servers through remote desktops but not be a member
>> of
>> the domain admins group. I have added him to the backup operators group
>> however he sitll does not have access to logon to the session.
>>
>> With out making any group policy changes is there a group I can add him
>> to
>> that will allow him to logon to the servers without changing each ts
>> server's RDP connection permissions?
>>
>>
>>


.



Relevant Pages

  • Re: Remote Desktop local policy error
    ... Double check that the domain admins group is still included in the local ... Allow logon through TS: Administrators, Remote Desktop Users ... I'm in the local administrators group and I'm the domain admin as well. ...
    (microsoft.public.windowsxp.security_admin)
  • Strange Windows XP Problem
    ... I have an XP build connected by Fibre to Windows 2000 AD servers. ... machine will allow domain admins to logon to the domain but prevents domain ... However, and here's the odd bit, it will allow the domain users to ...
    (microsoft.public.windowsxp.general)
  • No Domain Group shows up....
    ... ...in the local Administrators group. ... But in these servers, ... I noticed that it recognizes me as the domain admins even though D.A group ... to Administrators group, nothing but local administrator shows up. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Start again on the newbies networking problem. Re: Need help (of course) setting up network
    ... As you are working on this, do download the latest ... > servers that will help you later. ... ; guest account = pcguest ... ; logon script = %m.bat ...
    (Fedora)
  • Re: WMI in ASP fails on 2003 (err 80041003); works fine on 2000
    ... > Strike the comment about the interactive logon. ... I still don't see the need for delegation. ... >>> tested it on two servers with no problems. ... >>> interactive logon - thus WMI to remote machine should be a single hop) ...
    (microsoft.public.win32.programmer.wmi)

Loading