speckytecky Posted February 5, 2015 Posted February 5, 2015 (edited) I'm currently trying to allow an Admin Staff member access to Active Directory on our Server 2008 Standard Domain she can get to the log on screen but on entering her details gets the following message: To log on to this remote computer you must be granted the Allow log on through Terminal Services right. By default, members of the Administrator group have this right. If you are not a member of the Administrators group or another group that has this right or if the Administrator group does not have this right you must be granted this right manually. What do I need to change. I clearly don't want to give her full Admin rights. Edited February 5, 2015 by speckytecky
Steve21 Posted February 5, 2015 Posted February 5, 2015 Are you wanting AD access or remote desktop? If it's just AD access install the AD toolpack for Windows, and delegate access. If it's RD it'll need to add the user to the remote access group on the server. Steve 1
tmcd35 Posted February 5, 2015 Posted February 5, 2015 Log into the machine you want her to be able to RDP to and look at the local security groups. One of them will be for terminal server/remote desktop. Add her AD account to that security group. 1
chilbs Posted February 5, 2015 Posted February 5, 2015 you are best giving them an active directory task pad to the specific ou that you want them to access and delegated permissions. 1
Roberto Posted February 5, 2015 Posted February 5, 2015 I'm currently trying to allow an Admin Staff member access to Active Directory {...} What do I need to change. I clearly don't want to give her full Admin rights. Those two statements don't really go together. As others have said, you should give them delegated access to whatever it is they need via remote admin tools on their machine. Don't allow people who are not domain admins and who you don't want to be domain admins to log into a DC interactively.
fiza Posted February 5, 2015 Posted February 5, 2015 I'm currently trying to allow an Admin Staff member access to Active Directory on our Server 2008 Standard Domain What exactly will she be doing with the access?
speckytecky Posted February 5, 2015 Author Posted February 5, 2015 I'm off to Hospital for a day or so and want a contingency plan for if I'm not around. I just want to allow her to lock accounts down, add new users and reset passwords. None of the above seems to work when I try it. I was wondering if Delegating Control might be a way forward? What exactly will she be doing with the access?
fiza Posted February 5, 2015 Posted February 5, 2015 You want to create an MMC console taskpad view then and only give access to the user account area. https://thwack.solarwinds.com/community/solarwinds-community/geek-speak_tht/blog/2012/12/07/use-custom-taskpad-views-to-delegate-ad-tasks
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now