Jump to content

Recommended Posts

Posted (edited)

I'm currently trying to allow an Admin Staff member access to Active Directory on our Server 2008 Standard Domain she can get to the log on screen but on entering her details gets the following message:

 

To log on to this remote computer you must be granted the Allow log on through Terminal Services right. By default, members of the Administrator group have this right. If you are not a member of the Administrators group or another group that has this right or if the Administrator group does not have this right you must be granted this right manually.

 

What do I need to change. I clearly don't want to give her full Admin rights.

Edited by speckytecky
Posted

Are you wanting AD access or remote desktop?

 

If it's just AD access install the AD toolpack for Windows, and delegate access. If it's RD it'll need to add the user to the remote access group on the server.

 

Steve

  • Thanks 1
Posted
Log into the machine you want her to be able to RDP to and look at the local security groups. One of them will be for terminal server/remote desktop. Add her AD account to that security group.
  • Thanks 1
Posted
I'm currently trying to allow an Admin Staff member access to Active Directory
{...}
What do I need to change. I clearly don't want to give her full Admin rights.

 

Those two statements don't really go together. As others have said, you should give them delegated access to whatever it is they need via remote admin tools on their machine. Don't allow people who are not domain admins and who you don't want to be domain admins to log into a DC interactively.

Posted
I'm currently trying to allow an Admin Staff member access to Active Directory on our Server 2008 Standard Domain

 

What exactly will she be doing with the access?

Posted

I'm off to Hospital for a day or so and want a contingency plan for if I'm not around. I just want to allow her to lock accounts down, add new users and reset passwords. None of the above seems to work when I try it. I was wondering if Delegating Control might be a way forward?

 

What exactly will she be doing with the access?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...