Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Granting Terminal Server User Access for domain users

Status
Not open for further replies.

deankn

IS-IT--Management
Feb 22, 2003
30
0
0
US
Am trying to set up a 2003 terminal server in network with a win2k domain controller. I can access the ts only with users that are in the domain admins group on the dc. Non-admin users login brings error "to log on to this remote computer you must be granted the allow log on through terminal services...". Am unable to add domain users/groups to the remote desktop users group on the ts - only the name of the local computer appears in the "from this location" box.
FWIW I can remote desktop into the dc using a non-admin user.
I am assuming I am missing something obvious - any suggestions?
Thanks
Dean
 
Dean,
Even if you click on the "location" box, you don't have the choice of selecting the entire domain?

Kmills
 
When I go into computer management/local users and groups/remote desktop users/add the local computer name is in "from this location" - if i click the locations button the only location is the local computer - the ts is on the domain, and I can see the other domain computers.
Dean
 
Are you logging on as a local administrator or a domain administrator?
 
I am logging on as the domain administrator. Perhaps that's my problem?
 
No, you should be able to see your entire domain if you are logged in as a domain admin. This server is a member of the domain, right?
 
Do you have a GPO restricting Terminal Services? Have you allowed the users the right to remote access in AD?

This may have been checked, but it's good to cover all bases :)
 
Sorry for double..

Have you added them to the domain remote users group?
As regards the server, it does not appear to be on the domain correctly. Can you get it to replicate with the DC?

If you run set from the command line, you should be able to see if the TS has authenticated correctly.

Again, sorry if this has been automatically covered.
 
The ts seems to be joining the domain just fine - the users were granted rights to log on locally on the dc - users can remote desktop directly to dc without any problems(in remote admin mode)
 
Under services, is Remote Access Connection Manager started? How about Terminal Service?
 
Yes to both. As I said I can access ts with domain admins but not domain users. I think the main issue is that I cannot add domain users to the ts remote desktop users group.
 
check ur ddp gpo
add the users/group to the remote desktop users group in ad
is ur ts licens server up and running?
 
I got this to work - I believe what made it work was adding "remote desktop users" to "allow logon through terminal services" in the local policies on the terminal server.
Thanks for your help.
Dean
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top