Jump to content

Recommended Posts

Posted

Hello,

 

I have a user that needs to RDP to one of our Windows 2008 R2 servers, but everytime they try, they receive a message simply saying "Access Denied".

 

Checking the event log on the server doesn't show any particular alerts that relate.

 

The user is in a group that allows logon locally, remote desktop users, logon through terminal services. We have other people in the same groups and they can successfully logon.

 

The issue seems to somewhat relate to profiles. The user has a profile usernameRDS.v2 for which they have full control over. On the server there is an environment variable that converts %osver% to RDS

 

Within ADUC the profile path points to username%osver%.

 

I have ensured the user has full control over both of these folders, still no joy. I deleted the RDS folder in the hope this will be created when the user logs on...no joy.

 

However, if I totally remove the profile path from ADUC...then the user can successfully RDP the server.

 

Anyone else come across this?

Posted
Can you try deleting the local profiles on the client, server and give the user a new profile (romaing/mandatory whatever you use)
Posted

Ok looks like we found the issue....this turned out to be due to "Token Bloat" with the need to increase the MaxTokenSize.

 

MaxTokenSize and Kerberos Token Bloat - Just Blog&#39n - Site Home - TechNet Blogs

 

This is normally caused by being a member of too many groups. Not sure how the profile path related in anyway, but by increasing the Token size, rebooting the server, the "Access Denied" error went away

 

Hope others might find this useful ;)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...