Re: Can not log into my terminal server - logon error

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



This server is a domain controller then? If so, that would explain alot.
Also if it is, you are creating a security issue with having normal users
logging onto a domain controller.

Jeff Pitsch
Microsoft MVP - Terminal Server

Forums not enough?
Get support from the experts at your business
http://jeffpitschconsulting.com

"Phil Buzzette" <PhilBuzzette@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C8FA2793-F47A-4067-8C6C-D41C6808318A@xxxxxxxxxxxxxxxx
I am pretty sure I figured it out. I had to give them access to the
connection through the terminal services configuration. I had them as
members
of the group on the local machine and it still didn't work.

I have an OU created with specific log on usernames
that have a set GPO.

I mean that I have a domain controller that, through active directory, I
created a OU for the Terminal Service Users. I created a GPO for the users
as
a "lockdown" method.

"Vera Noest [MVP]" wrote:

Then you probably are not connecting to the console session after
all.

A console session (which is only available to Administrators), is
started by typing "mstsc /console" at a command prompt.

If you just type "mstsc", or you use the Remote Desktop Client,
then you are *not* connecting to the console session.

As the error messages says, your users must be members of the local
build-in group "Remote Desktop Users" on your Terminal Server. Can
you confirm that this is the case?
And what exactly do you mean with:

I have an OU created with specific log on usernames
that have a set GPO.

_________________________________________________________
Vera Noest
MCSE, CCEA, Microsoft MVP - Terminal Server
TS troubleshooting: http://ts.veranoest.net
*----------- Please reply in newsgroup -------------*

=?Utf-8?B?UGhpbCBCdXp6ZXR0ZQ==?=
<PhilBuzzette@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote on 02 jun 2006:

I am not familiar with how to remove the console option.

"Jeff Pitsch" wrote:

Simply remove the console option.

Jeff Pitsch
Microsoft MVP - Terminal Server

Forums not enough?
Get support from the experts at your business
http://jeffpitschconsulting.com

"Phil Buzzette" <PhilBuzzette@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote
in message
news:BE0FF4FC-D89F-4998-8460-CBFD444611AB@xxxxxxxxxxxxxxxx
Not to be ignorant, but how do I go about correcting this? I
don't need administrators to connect. The normal users simply
need to log in to run a simple time clock application.

"Jeff Pitsch" wrote:

the console session only allows administrators to connect.
the console session is not to be used by normal users and is
not controlled by TS in application mode.

Jeff Pitsch
Microsoft MVP - Terminal Server

Forums not enough?
Get support from the experts at your business
http://jeffpitschconsulting.com

"Phil Buzzette" <PhilBuzzette@xxxxxxxxxxxxxxxxxxxxxxxxx>
wrote in message
news:5108C880-5E85-42FB-B4EA-9DAC3798BDFD@xxxxxxxxxxxxxxxx
I am connecting to the console session and the server is
configured in
application mode.

"Jeff Pitsch" wrote:

Are you connecting to the console session? Go to Run and
type mstsc.exe
then hit enter, then try to connect. as well, make sure
you have terminal
services installed in application mode (add/remove
programs, windows components.

Jeff Pitsch
Microsoft MVP - Terminal Server

Forums not enough?
Get support from the experts at your business
http://jeffpitschconsulting.com

"Phil Buzzette" <PhilBuzzette@xxxxxxxxxxxxxxxxxxxxxxxxx>
wrote in message
news:1846AB70-2CA4-4AC7-838C-764701030639@xxxxxxxxxxxxxxxx
"To log on to this remote computer, you must be granted
the Allow log
on
through terminal services right. By default, members of
the Remote desktop
users group have this right. If you are not a member of
the Remote Desktop
Users group or another group that has this right, or if
remote desktop
user
group does not have this right, you must be granted
this right manually."

I have my machine, my terminal server, and my server
with active directory.
I have an OU created with specific log on usernames
that have a set GPO.
When
I open up rdp on my local pc and remote into my
terminal server, I get
the
above error message. The user account that I am using
is not an admin,
but
is
a domain user and a remote desktop user. I am wondering
what I might be
missing. If I make the user a domain admin, it works
fine, but that will
not
work in my situation. Any ideas or recommendations
would be greatly appreciated. Thank you in advance for
those who take the time to assist
me.



.



Relevant Pages

  • The local policy of this system does not allow you to log on inter
    ... I also checked "Deny Logon Locally" and nothing is configured. ... I am trying to logon to the Terminal Server ... I have added the group Domain Users to the Builtin Group Remote Desktop ...
    (microsoft.public.windows.terminal_services)
  • RE: The local policy of this system does not allow you to log on inter
    ... If the server is a 2003 Member Server, then the only things required for RDP ... Member of the local Remote Desktop User's Group, or a group with User & ... Users do NOT require the logon locally right for 2003 TS, ... Microsoft MVP - Terminal Server ...
    (microsoft.public.windows.terminal_services)
  • Re: Users can only login to one TS server
    ... then add the domain group Remote Desktop Users to the local Remote ... MCSE, CCEA, Microsoft MVP - Terminal Server ... show up on any server running terminal services? ...
    (microsoft.public.windows.terminal_services)
  • User was forced to log off once he logged on to TS on 2k3 without
    ... Server: Win2k3 Standard, Remote Desktop enabled, domain controller. ... any clients using Remote desktop connection software. ...
    (microsoft.public.win2000.termserv.clients)
  • Re: Remote Desktop Users group
    ... the local Remote Desktop Users group. ... MCSE, CCEA, Microsoft MVP - Terminal Server ... > found in AD and the built in group on the member server? ...
    (microsoft.public.windows.terminal_services)