Group:  English: Windows Server ยป microsoft.public.windows.terminal_services
Thread: REMOTE DESKTOP CONNECTION

DotNetBag
.NET Development Newsgroups

HTVi
TV Discussion Newsgroups

Our Hot Pick: Rising Antivirus 2006 - Certified by TUV & Checkmark! Get 10% discount by entering this coupon code: ONDISCOUNT10
Rising Antivirus 2006

REMOTE DESKTOP CONNECTION
HMO Fallen Angel 12.07.2007 21:38:11
Hi eveybody,
Before, we used to have a windows 2000 as our domain controller and it was
the terminal server too, and we can RDC to this server. Then, we got a new
server, installed win 2003 server 'migrated' our 2000 domain to a 2003 domain
and right now they are co-existing.
We did this because we need to move our application from the win 2000 server
to the new 2003 server.
Right now users are connecting to the 2000 server using using terminal
server without any problems.
I have already installed terminal server and its licenses on the new win
2003 server but when i try to connect using RDC i'm getting the error:

"To log on this remote computer, you must be granted the Allow log on
through Terminal Services right. By default, members of the Remote Desktop
Users group have this right. If you are not a member of the Remote Desktop
group or another group thas has this right, or if the Remote Desktop User
group does not have this right, you must be grantes this right manually"

I'm trying (on the win 2003 server) the local computer policy/computer
configuration/ windows setting/ security settings/local policies/user rights
assignment/ Allow log on terminal services and allow the Remote Desktop User
group, but there is no Remote Desktop User group available. I tried then
selecting a single user and allowing this option for this user and is still
not working.

What can be the problem? I don't have any problem connecting to the 2003 as
an administrator.

I need to make this work before we can dcpromo the win 2000 server and just
keep the 2003 server

Any help will be really appreciated.

--
HMO Fallen Angel
Re: REMOTE DESKTOP CONNECTION
"Vera Noest [MVP]" <vera.noest[ at ]remove-this.hem.utfors.se> 12.07.2007 22:33:13
So the 2003 server is a DC, correct?
I assume that it is *not* recommended to run TS on a DC, for both
performance and -most of all-security reasons. After all, by
installing TS, you turn your DC into a multi-user workstation!
Can't you demote the W2K server to a member server and then upgrade
it to 2003? That would give you a 2003 domain with a dedicated TS,
which is a much better environment.

That said, you'll have to make your users members of the Domain
Local built-in group Remote Desktop Users in AD and add that group to
this setting in the Default Domain Controller Policy:
Computer Configuration - Windows Settings - Security Settings - Local
Policies - User rights Assignment
"Allow log on through Terminal Services"
_________________________________________________________
Vera Noest
MCSE, CCEA, Microsoft MVP - Terminal Server
TS troubleshooting: http://ts.veranoest.net
___ please respond in newsgroup, NOT by private email ___

=?Utf-8?B?SE1PIEZhbGxlbiBBbmdlbA==?=
<HMOFallenAngel[ at ]discussions.microsoft.com> wrote on 12 jul 2007 in
microsoft.public.windows.terminal_services:

[Quoted Text]
> Hi eveybody,
> Before, we used to have a windows 2000 as our domain controller
> and it was the terminal server too, and we can RDC to this
> server. Then, we got a new server, installed win 2003 server
> 'migrated' our 2000 domain to a 2003 domain and right now they
> are co-existing. We did this because we need to move our
> application from the win 2000 server to the new 2003 server.
> Right now users are connecting to the 2000 server using using
> terminal server without any problems.
> I have already installed terminal server and its licenses on the
> new win 2003 server but when i try to connect using RDC i'm
> getting the error:
>
> "To log on this remote computer, you must be granted the Allow
> log on through Terminal Services right. By default, members of
> the Remote Desktop Users group have this right. If you are not a
> member of the Remote Desktop group or another group thas has
> this right, or if the Remote Desktop User group does not have
> this right, you must be grantes this right manually"
>
> I'm trying (on the win 2003 server) the local computer
> policy/computer configuration/ windows setting/ security
> settings/local policies/user rights assignment/ Allow log on
> terminal services and allow the Remote Desktop User group, but
> there is no Remote Desktop User group available. I tried then
> selecting a single user and allowing this option for this user
> and is still not working.
>
> What can be the problem? I don't have any problem connecting to
> the 2003 as an administrator.
>
> I need to make this work before we can dcpromo the win 2000
> server and just keep the 2003 server
>
> Any help will be really appreciated.
Re: REMOTE DESKTOP CONNECTION
HMO Fallen Angel 12.07.2007 22:46:00
thanks for your reply Vera,
the main reason for having only 1 server is, of course, money. So, after we
can move everything to the new one we'll see what we can do with the old 2000
server.
About the Remote Desktop Users Group, my problem is that i don't have that
group, or i can't see it on my Active Directory, or is there any trick to
access this group?
--
HMO Fallen Angel


"Vera Noest [MVP]" wrote:

[Quoted Text]
> So the 2003 server is a DC, correct?
> I assume that it is *not* recommended to run TS on a DC, for both
> performance and -most of all-security reasons. After all, by
> installing TS, you turn your DC into a multi-user workstation!
> Can't you demote the W2K server to a member server and then upgrade
> it to 2003? That would give you a 2003 domain with a dedicated TS,
> which is a much better environment.
>
> That said, you'll have to make your users members of the Domain
> Local built-in group Remote Desktop Users in AD and add that group to
> this setting in the Default Domain Controller Policy:
> Computer Configuration - Windows Settings - Security Settings - Local
> Policies - User rights Assignment
> "Allow log on through Terminal Services"
> _________________________________________________________
> Vera Noest
> MCSE, CCEA, Microsoft MVP - Terminal Server
> TS troubleshooting: http://ts.veranoest.net
> ___ please respond in newsgroup, NOT by private email ___
>
> =?Utf-8?B?SE1PIEZhbGxlbiBBbmdlbA==?=
> <HMOFallenAngel[ at ]discussions.microsoft.com> wrote on 12 jul 2007 in
> microsoft.public.windows.terminal_services:
>
> > Hi eveybody,
> > Before, we used to have a windows 2000 as our domain controller
> > and it was the terminal server too, and we can RDC to this
> > server. Then, we got a new server, installed win 2003 server
> > 'migrated' our 2000 domain to a 2003 domain and right now they
> > are co-existing. We did this because we need to move our
> > application from the win 2000 server to the new 2003 server.
> > Right now users are connecting to the 2000 server using using
> > terminal server without any problems.
> > I have already installed terminal server and its licenses on the
> > new win 2003 server but when i try to connect using RDC i'm
> > getting the error:
> >
> > "To log on this remote computer, you must be granted the Allow
> > log on through Terminal Services right. By default, members of
> > the Remote Desktop Users group have this right. If you are not a
> > member of the Remote Desktop group or another group thas has
> > this right, or if the Remote Desktop User group does not have
> > this right, you must be grantes this right manually"
> >
> > I'm trying (on the win 2003 server) the local computer
> > policy/computer configuration/ windows setting/ security
> > settings/local policies/user rights assignment/ Allow log on
> > terminal services and allow the Remote Desktop User group, but
> > there is no Remote Desktop User group available. I tried then
> > selecting a single user and allowing this option for this user
> > and is still not working.
> >
> > What can be the problem? I don't have any problem connecting to
> > the 2003 as an administrator.
> >
> > I need to make this work before we can dcpromo the win 2000
> > server and just keep the 2003 server
> >
> > Any help will be really appreciated.
>
Re: REMOTE DESKTOP CONNECTION
"Vera Noest [MVP]" <vera.noest[ at ]remove-this.hem.utfors.se> 13.07.2007 09:51:29
Mmm, it should be there, at least after a fresh install of AD on a
2003 server. But maybe it's not created when the 2003 server is made
a DC in an existing W2K AD.
I've never done any of this myself, so no guarantees, but I guess
that you could manually create a Domain Local security group
"Terminal Server Users" and add that group to the user right
assignment "Allow log on through Terminal Services" in the Default
Domain Controller Policy.

Note that I would *not* call this manually created group "Remote
Desktop Users", to be able to distinguish it from the Builtin group.

_________________________________________________________
Vera Noest
MCSE, CCEA, Microsoft MVP - Terminal Server
TS troubleshooting: http://ts.veranoest.net
___ please respond in newsgroup, NOT by private email ___

=?Utf-8?B?SE1PIEZhbGxlbiBBbmdlbA==?=
<HMOFallenAngel[ at ]discussions.microsoft.com> wrote on 13 jul 2007 in
microsoft.public.windows.terminal_services:

[Quoted Text]
> thanks for your reply Vera,
> the main reason for having only 1 server is, of course, money.
> So, after we can move everything to the new one we'll see what
> we can do with the old 2000 server.
> About the Remote Desktop Users Group, my problem is that i don't
> have that group, or i can't see it on my Active Directory, or
> is there any trick to access this group?

Home | Search | Terms | Imprint | Contact
Newsgroups Reader - provided by WiredBox.Net