Re: "Allow log on through Terminal Services" in GP: How does it work?
Right on both counts, provided . . .
There are basically two things carried by the Remote Desktop Users
group, as you have indicated a couple times: the user right to log on
through TS, and the permissions on the rdp-tcp connectoid. However,
I often recommend that people take control over the Users group on
their domain joined machines, in which case they may have removed
Authenticated Users, Domain Users, and/or Interactive from Users
and/or from the user rights normally granted to Users . The precise
impact would depend on how they have hardened their server. In
most all cases, sufficient grants over Windows binaries and temp
areas does result if, in this case, the group made a member of the
Remote Desktop Users group is also made a member of Users, both
of course doable via GPO targetting.
Roger
"Vera Noest [MVP]" <Vera.Noest@remove-this.hem.utfors.se> wrote in message
news:Xns99768E5EFCDECveranoesthemutforsse@207.46.248.16...
> That's not correct, Rob.
> For the mentioning of the "Remote Desktop Users" group we can
> deduce that the TS is running 2003. Then you do *not* need the user
> right to Logon Locally. That was true on W2K, but not on 2003.
>
> And without the proper permissions on the rdp-tcp connection, you
> won't be able to connect, no matter what Logon user rights you
> have.
> _________________________________________________________
> Vera Noest
> MCSE, CCEA, Microsoft MVP - Terminal Server
> TS troubleshooting: http://ts.veranoest.net
> *----------- Please reply in newsgroup -------------*
>
> =?Utf-8?B?Um9iIChNaWNyb3NvZnQp?=
> <RobMicrosoft@discussions.microsoft.com> wrote on 22 jul 2007:
>
>> Allow logon through terminal Services as well as allow logon
>> locally should let you logon with those users as long as you are
>> running Terminal Server and not remote desktop.
>>
>> "roga" wrote:
>>
>>> All I want to do is set a group policy which allows members of
>>> an existing security group to log on via RDP without me having
>>> to make them members of the local "remote desktop users" group.
>>>
>>> The group policy "Allow log on through Terminal Services" "
>>> looks like it should do the job, but I have never managed to
>>> get it to work.
>>>
>>> can someone give me some pointers?
>>>
>>> regards
>>>
>>> roga