Jump to content

Recommended Posts

Posted (edited)

Hi, I am running Windows 10 clients on a 2016 server.

All users have membership of both Domain Users and Remote Desktop Users, however if I try and connect to a Windows 10 client computer, it refuses to let me log in as a domain user, showing this error:

Remote Desktop Connection

The connection was denied because the user account is not authorised for remote login.

 

If I log in as domain administrator via RDC, there are no issues. Where am I going wrong?

Firewall is switched off via Group Policy for all systems.

 

I also have a GPO enabled for Computer Config>Windows Settings>Security Settings>Local Policies>User Rights Assignment>Allow log on through Remote Desktop Services> Everyone & my user security group.

Edited by talksr
  • 1 month later...
Posted
Have you tried adding yourself to the remote desktop group on AD even though your a domain admin ?

 

Sorry for the late reply. Yes I have. As an example, what I would like to do, is be able to log in as a teacher user, on their own computer, so I can check that their settings are coming up as expected.

I have added the teacher users security group to a GPO I created. I configured it in Computer Configuration>Policies>Windows Settings>Local Policies/User Rights Assignment>Allow logon through Terminal Services> Enabled for Builtin\Remote DesktopUsers, domain.internal\TeachingStaffGroup, Everyone.

 

I have forced GPUpdate on many stations, but still it does not work.

 

For reference, I am running server 2016 with Windows 10 clients.

Posted (edited)
Have your tried to connect from one client to another but adding in the domain user which your connecting to which machine

 

Yes, if I try from another client or even the frdc server, I just get "The connection was denied because the user account is not authorise for remote log-in. I have just re-checked on AD, the user I am trying to log in as is a member of Remote Desktop Users.

 

What I am finding is that a lot of the client computers do not have any Remote Desktop Users listed in System settings. If I add the security groups manually to a computer, and then try again, it works.

But this is very time consuming. Is it possible to do this via a policy to all stations?

Edited by talksr

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...