Permit Group to logoff and shadow users (2012 R2)

Hello everyone,
I'm looking for a way to grant users permission to shadow und logoff RDS user sessions.
To do this I first need to get the user's session host und unified session id:
$Session = Get-RDUserSession -ConnectionBroker $ConnectionBroker -CollectionName "MyCollection" -ErrorAction Stop | Where {$_.UserName -eq $CommonName}
After that I can use the information to either logoff or shadow the user.
For shadowing:
mstsc /v:$HostServer /shadow:$SessionId /control
For LogOff:
Invoke-RDUserLogoff -Force -HostServer $Session.HostServer -UnifiedSessionID $Session.UnifiedSessionId -ErrorAction Stop
My problem:
To run these commands the user needs admin privileges, which is not what you want for a first level supporter.
My question:
Is there a way to allow a group/user to retrieve the session ID's from the Connection Broker and Logoff/Shadow without granting them admin privileges?
In case there is no way to grant those specific permissions, what are the permissions the user requires on which machines (broker, hosts?)?

Hi,
Thank you for posting in Windows Server Forum.
You can use provide access to shadow session to normal user other than administrator. To allow non-administrators permissions to shadow you can use the following command which is also applicable for Windows Server 2008 R2 
wmic /namespace:\\root\CIMV2\TerminalServices PATH Win32_TSPermissionsSetting WHERE (TerminalName="RDP-Tcp") CALL AddAccount "domain\group",2
More information:
RDS 2012 Configure Permissions for Remote Desktop Services
Connections
Hope it helps!
Thanks.
Dharmesh Solanki

Similar Messages

  • Forms Authentication Error: User '' does not have required permissions. Verify that sufficient permissions have been granted and Windows User Account Control (UAC) restrictions have been addressed

    I created a custom security extension following the steps listed in the Readme_Security Extension Sample. It works fine if I login as the user that is specified AdminConfiguration section of the rsreportserver.config file but if I
    log in as another user, I get this error: User '' does not have required permissions. Verify that sufficient permissions have been granted and Windows User Account Control (UAC) restrictions have been addressed.  I've added the user to both System Administrator
    and System User roles to try to get it to work but still no luck.
    Does anyone know how to fix this?
    Thanks.

    Hi MetronM,
    The issue is due to that user have no permission to access the report server. In report manager, Reporting Services includes predefined roles that we can assign to users and groups to provide immediate access to a report server. Each role defines a collection
    of related tasks.
    You can refer to the following steps to assign corresponding role to the user.
    Open report manager.
    Click “Folder Setting” button. 
    Click “New Role Assignment” icon.
    Type the user name and select the corresponding role.
    There is an article about Granting Permissions on a Native Mode Report Server, you can refer to it.
    http://technet.microsoft.com/en-us/library/ms156014.aspx
    Regards,
    Alisa Tang
    Alisa Tang
    TechNet Community Support

  • User 'Levent2-PC\Levent2' does not have required permissions. Verify that sufficient permissions have been granted and Windows User Account Control (UAC) restrictions have been addressed.

    I have run Report Manager which show the below error
    and
    web url show below error
       What should I do for solve this error?
        Plz give replay quicKly 

    Hi tusharshinde,
    Based on my understanding, you come across an issue when you try to access report manager and report server.
    In Reporting Service, after installing a new report server, only users who are members of the Local Administrators group have permissions to access report server. If we want to grant permissions for other users to access report server, we should add users
    to an item-level role and system-level role. Please refer to this article:
    Grant User Access to a Report Server (Report Manager).
    According to the screenshots, it’s clear that you don’t have sufficient permission to access report manager and report server. So in this scenario, please make sure you are members of local administrators group. To fix the issue, you could run IE browser
    as administrator  and add your account to an proper item level role and system-level role. If issue persists, please temporarily change the User Access Control settings to “Never notify”. For more information, please refer to articles below:
    SQL Server Reporting Services Report Manager Site Permissions Error After Installation
    rsAccessedDenied - Reporting Services Error
    If you have any question, please feel free to ask.
    Best regards,
    Qiuyun Yu

  • Client application freezes permanently when one user logoff and another user take that session on windows server 2008 r2

    Hi,
    we have windows server 2008 r2 and In our application there are three server and on e client application.
    My client application freezes on a specific scenario.
    Steps taken to hang are following:-
    1. start client application
    2. open an module named by XYZ
    3. login to remote machine with another session./ Another user login from their computer.
    4. connect with the session which have client application opened.
    5. Whenever the session is forcibly taken client application becomes unresponsive.

    Hello,
    The Windows Desktop Perfmon and Diagnostic tools forum is to discuss performance monitor (perfmon), resource monitor (resmon), and task manager, focusing on HOW-TO, Errors/Problems, and usage scenarios.
    Since your post is off-topic, I am moving it to the
    off topic forum.
    Karl
    When you see answers and helpful posts, please click Vote As Helpful, Propose As Answer, and/or Mark As Answer.
    My Blog: Unlock PowerShell
    My Book:
    Windows PowerShell 2.0 Bible
    My E-mail: -join ('6F6C646B61726C406F75746C6F6F6B2E636F6D'-split'(?<=\G.{2})'|%{if($_){[char][int]"0x$_"}})

  • How to create groups and assign users thru program

    Hi,
    I am planning to create groups by program and assign users to them based on some condition.Once users are assigned to those groups we need to change the Language value for those users in User profile
    We are using Central User Administration.
    Please let me know the solution
    Thanks
    Bala Duvvuri

    probably you can use this code to create a group
    IGroupFactory groupFact = UMFactory.getGroupFactory();  
    IGroup group = groupFact.newGroup(wdContext.currentContextElement().getGroup()); 
       group.commit();
    for this required com.sap.security.api.jar

  • How do I setup users to create files in /Users/Shared with group permissions default to rw and not just r?

    I have setup my iMac with 4 user accounts (for the wife and kids).   Some files I would like them to all have access to and that access be read / write.
    I believe I should use the /Users/Shared directory but when a user creates a file there the permissions are rw for the owner but only r for the group & other.   I would like the permissions to default to rw also for group when the file is created so any of them can edit the shared file.
    Basically the umask is defaulting as 0022 and I would like it to be 0002.
    How can I set their account behavior to be this way by default?  Thanks

    You should be able to take the permissions you have set and "apply to enclosed items." I am trying to attach a picture of what this looks like so my apologies if it does not work.
    Highlight your folder you want and go to File>Get Info or command+I and at the bottom where it has Sharing and Permissions, click the lock button to authenticate. Click the gear and click "apply to enclosed items". See if that works.

  • I have upgraded Apple Aperture from version 2 to version 3 and I'm having a problem with the "Highlights and Shadows" adjustment. According to the user's manual, I should have access to an advanced disclosure triangle which would allow me to adjust mid co

    I have upgraded Apple Aperture from version 2 to version 3 and I'm having a problem with the "Highlights and Shadows" adjustment. According to the user's manual, I should have access to an advanced disclosure triangle which would allow me to adjust mid contrast, colour, radius, high tonal width and low tonal width.
    If anyone has any suggestions as to how to access this advanced section, I'd be most grateful.

    Hi David-
    The advanced adjustments in the Highlights & Shadows tool were combined into the "Mid Contrast" slider in Aperture 3.3 and later. If you have any images in your library that were processed in a version of Aperture before 3.3, there will be an Upgrade button in the Highlights & Shadows tool in the upper right, and the controls you asked about under the Advanced section. Clicking the Upgrade button will re-render the photo using the new version of Highlights & Shadows, and the Advanced section will be replaced with the new Mid Contrast slider. With the new version from 3.3 you probably don't need the Advanced slider, but if you want to use the older version you can download it from this page:
    http://www.apertureexpert.com/tips/2012/6/12/reclaim-the-legacy-highlights-shado ws-adjustment-in-aperture.html

  • How to create groups and add users?

    Hello,
    I have created 3 groups as Portal_Admin and added 2 users for each group.
    When I am trying to grant permissions to these groups to the Applications owned by Portal30( I have logged in as portal30 at this point), I am unable to see these groups but am able to see these individual users.
    I am trying to grant access to individual menu items/sub menus of a Portal Menu.
    Is it correct way to do things?
    Or am I wrong somewhere?
    My Idea:
    I would like to create 20 users 10 of each belong to particular Oracle schema and then organize these 20 as groups
    who will access certain application objects.
    I wanted to give Admin an option to add/del/modify users to and from a Group once initial setup is done.
    We really stopped here.
    Your help is appreciated.
    Thanks
    Madhav

    It's a bug.
    Type the name of the group you want to add the user to and click apply, if you typed it correctly the the group name will appear.
    We are building a fix for this.
    Portal PM

  • M70: Permissions, wallpaper and limited user

    Hi,
    I have spent some time (i.e. a few days of mucking around) setting up a new M70 (PSM70A-T00E) notebook which has WinXPSP2 preinstalled (on an all-but-useless recovery DVD without the alleged "expert" option, but that's another story).
    When Windows was first installed, I configured the (default) administrator and one user account (called "aburdeni"). By default, both accounts had administrator permissions.
    After setting things up the way I like them, I am now trying to convert the user account to a limited account.
    The usual method of "control panel->user accounts->...->change account type" doesn't work as it claims that there is only one account on the system (even though there's the one with the username "administrator", which it ignores for some reason).
    To override this, I logged in as administrator and ran lusrmgr.msc. I then added user "aburdeni" to the User group and removed them from the Administrator group.
    Things broke.
    What I have noticed now is that:
    * The default Toshiba theme doesn't stick (no wallpaper, just a plain grey backdrop)
    * Control panel reverted back to the default hierarchical style, and clicking on the give-it-to-me-the-way-I-like-it text on the left-hand side didn't do anything.
    * Other settings (taskbar, start menu style) reverted back to the default.
    There are probably countless other things that broke, but I have yet to find them.
    Setting the account to Power User instead of User made no difference. Things only started working again when I added the account back into the Administrator group.
    Is there any way to have things work while logged in as an unprivileged user?
    Thanks,
    Adam
    BTW: I'm from Australia, if that makes a difference (different settings for the default install?)

    Hello Adam
    As far as I know there is no difference in which country you live because operating systems are the same for all countries and some different settings depending on country are not known to me.
    Please delete all created accounts. Log in as administrator and then create a new account. First step is to give the name for this new account and click on Next. Second step is to define this user (administrator rights or even limited user). Choose limited option and end the wizard.
    Use Windows + L key combination and try to log in as limited user. There should not be any problem. The background picture and everything else will be set like for the first time.
    You can make a small test and try to start Toshiba power utility. You will see that there is no chance to start it and change anything. It can be used just by administrator.
    Please try again. It must works.
    Good luck!!!

  • What  is difference between user group and reference user group?

    hi
    guys,
            what  is difference between user group and reference user group? 
    your regards
      p.suresh

    Hi ,
    Chk the link below for your clarifiacation.
    http://help.sap.com/erp2005_ehp_03/helpdata/EN/5c/c1c81c445f11d189f00000e81ddfac/frameset.htm
    Hope it helps.
    Regards,
    Amit
    Edited by: Amit Kotwani on Sep 2, 2008 2:15 PM

  • How do i use an active directory group for vpn and not all user

    hi all,
    i have an asa 5515x...
    how do i use a particular group in active directory to have vpn/anyconnect access?  right now i believe it's for all user on my current config,
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    !integrate with active directory
    aaa-server LDAPSERVERS protocol ldap
    aaa-server LDAPSERVERS (vlan192) host 10.0.0.2
    ldap-base-dn dc=company,dc=com
    ldap-scope subtree
    ldap-naming-attribute sAMAccountName
    ldap-login-password 12345678
    ldap-login-dn cn=administrator,cn=Users,dc=company,dc=com
    server-type auto-detect
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    say i want this "vpn-group" object group in AD and my vpn is only anyconnect and no other vpn types.
    thanks for any comment you may add.

    The best way is to use Dynamic Access Policies (DAP). Cisco has a white paper (here) that shows how one can choose the LDAP group as one of the DAP criteria.
    DAP requires the Advanced Endpoint Assessment feature, so your licensing must support that.

  • Hi I do not want iTunes to open up automatically when I turn on my macbook pro.  I tried going to System Preferences Users and Groups Login Items and then I took iTunes off the list but it still opens up automatically when I turn on my laptop.

    Hi I do not want iTunes to open up automatically when I turn on my macbook pro.  I tried going to System Preferences>Users and Groups>Login Items and then I took iTunes off the list but it still opens up automatically when I turn on my laptop. What should I do?

    Hi r,
    Make sure you close iTunes before shutdown.  And you're quite welcome.

  • How to create a dynamic menu for each group of responsibility and  user

    Hi
    I am using Jdev 11.1.1.6 and new to ADF, my application require to populate menu which would be different for different groups of user, and the user in each group would have different submenu depends on their responsibilities assigned to each one of them.
    so on the top level would be menu_top_item1, menue_top_item2
    |-->submenu1_1 |-->submenu2_1
    |-->submenu1_2 |-->submenu2_2
    also the menu would need to be on_mouse_over to show the submenu items or collapsed back.
    any idea what would be the best approch? or is there any example around?
    thanks a lot

    You can use ADF Security to control access to menu options.
    More about ADF Security here:
    http://download.oracle.com/otn_hosted_doc/jdeveloper/11gdemos/AdfSecurity/AdfSecurity.html
    If you also use WebCenter you might use their menuing option:
    https://blogs.oracle.com/shay/entry/webcenter_portal_intro_for_adf

  • How does schedule with RESTful API a Webi report for a group of users ("Schedule For" to "Schedule for specified users and user groups" with one or more users/groups)?

    SAB BO 4.1 SP1
    Does it have an RESTful API to schedule a Webi report with the parameter to specify a group of users ("Schedule For" to "Schedule for specified users and user groups" with one or more users/groups)?

    Hello Ricardo,
    have you try a call like this one ?
        <schedule>
          <name>"test"</name>"
          <format type=\"webi\"/>
          <destination>
            <inbox>
             <to>userId1,userId2,userId3,groupId1,groupId12</to>
            </inbox>
          </destination>
        </schedule>
    Regards
    Stephane

  • Unable to download from AppStore, updates,etc.Messages 'the installer is damaged' to 'there might be a problem with file ownership and permissions.' I am the owner and only user of a new MBP. What could be going on?

    Is anyone having the same type of problems I'm having with Lion. I have a new MacBook Pro, received 7 weeks ago, preinstalled with Leopard 10.6.7. I didn't migrate anything from my old iMac, wanted a clean install from the Apple Store. While there, I asked for the upgrade to Lion 10.7, however their system was down.
    I  installed it myself, wirelessly about a week later, and Apple emailed me a receipt. Now, I've had to call support directly last week when I lost Mail, Address Book, was unable to open Preview or iTunes, among other problems. Seemed fixed after a session that baffled even the store tech.  Now I am unable to download or install the recent Mac updates for Lion, from the App Store, could not install Adobe Reader, etc. Messages range from 'A network error has occured - Check your Internet connection and try again' to 'The Installer is damaged and cannot open the package. There may be a problem with file ownership or permissions.'  All fail and I'll probably have to call Apple again. I am frustrated beyond words.  Logs 'Install's runner tool is not properly configured as a setuid tool', domain errors, 'attempt to write a readonly database, and on and on. I have barely done a thing on this computer except search online for help with these problems. Safari gives me a 'You are not connected to the internet' too often. Diagnostics disagrees. I do see wi-fi problems in the forum. Disk and permissions were fine at the beginning of the earlier problems, checked first by support tech. I'm not sure if support tech even knew. I was just happy they were fixed. Anyone have these download and/or install problems after a 'clean bill of health' so to speak, only a week ago?

    Let's try the following user tip with that one:
    "There is a problem with this Windows Installer package ..." error messages when installing iTunes for Windows

Maybe you are looking for