Sign-in through remote Desktop Services

To sign in remotely you need the right to sign through remote Desktop Services. By Defaults members of the administrators
Group have this right, if the group you are in doesnot have this right or if the righthas been removed from the
administrators group you need to be granted this right manually

Actually, the user needs to be member of "Remote Desktop Users" group to have this right, is not necessary to do this editing the user rights.
Jesús Peñaranda| MCP,MCT,MCTS,MCITP,MCSA,MCSE

Similar Messages

  • Allow log on through Remote Desktop Services Group Policy for Domain Controllers

    Hello,
    We want to allow our Helpdesk Operators to be able to connect to Domain Controllers with the Remote Desktop Services. This is by default not allowed but according to many sites, it should be able to configure by using a Group Policy.
    We made a new Group Policy with the setting 'Allow log on through Remote Desktop Services' and 'Allow log on locally' (as an extra for testing) and applied Security Filtering to only use it for a specific Security Group. Our test user is a member of this
    security group and should be able to access the Domain Controllers now. However this isn't working.
    The error message we receive upon trying to connect:
    The connection was denied because the user account is not authorized for remote login.
    For troubleshooting, we also applied the Security Group for that setting in the Default Domain Controllers Policy but that doesn't seem to work either. We want to avoid customization on our Default Domain Controllers Policy but this was just a test case
    for solving our problem.
    What should we do to solve our problem?
    I hope to hear from you soon.
    Thanks in advance.

    Hi, I just found out what the problem was. This site helped me alot:
    http://blogs.technet.com/b/askperf/archive/2011/09/09/allow-logon-through-terminal-services-group-policy-and-remote-desktop-users-group.aspx
    In my case, I had the group added to the Allow Logon Through Remote Desktop Services but was not added to the Builtin\Remote Desktop Users group. After knowing this I made some changes to our situation and are now using the builtin\Remote Desktop Users group
    rather than a new self made Security Group. I also added the Remote Desktop Users to the Allow Logon Through Remote Desktop Service in the Default Domain Controllers Policy as this is not done by default. By default only the Domain Administrators are able
    to logon through remote desktop services.
    You do not need the 'Log on Locally' permission within the Group Policies.
    In short:
    Add the desired users/groups to the 'Builtin\Remote Desktop Users' security group.
    Add the 'Builtin\Remote Desktop Users' security group to the 'Allow Logon Through Remote Desktop Services' within the 'Default Domain Controllers Policy'.
    Thank you anyway for the fast reply.
    Have a nice day!

  • How to enable users to access windows 2012 through remote desktop client on windows XP SP3

    Hi I have just installed Windows Server 2012 and trying to give access to the users. The users are on windows XP Pro SP3 remote desktop client (Shell and control version 6.1.7600 with Remote Desktop Protocol 7.0 support). 
    I have enabled the windows server 2012 remote desktop users through "control panel -> systems and security ->  Remote access" for the users. When I try to connect to the windows server as administrator, it is getting connected.
    But when I try to connect as other users I get the following message.
    "To sign in remotely, you need the right to sign in through Remote Desktop Services. By default members of the Administrators group have this right. If the group you're in does not have the right, or  if the right has been removed from the Administrators
    group, you need to be granted the right manually."
    Is there any other setting to be done to eanble the Remote Desktop for the users.

    Hi I have just installed Windows Server 2012 and trying to give access to the users. The users are on windows XP Pro SP3 remote desktop client (Shell and control version 6.1.7600 with Remote Desktop Protocol 7.0 support). 
    I have enabled the windows server 2012 remote desktop users through "control panel -> systems and security ->  Remote access" for the users. When I try to connect to the windows server as administrator, it is getting connected.
    But when I try to connect as other users I get the following message.
    "To sign in remotely, you need the right to sign in through Remote Desktop Services. By default members of the Administrators group have this right. If the group you're in does not have the right, or  if the right has been removed from the Administrators
    group, you need to be granted the right manually."
    Is there any other setting to be done to eanble the Remote Desktop for the users.
    Have you tried adding those users to the "Remote Desktop Users" group? It's in Active Directory Users and Computers and it's a Built-In group. Might want to give that a try ...
    - JJ

  • Cannot Get Remote Desktop Service to Work

    On Windows 8.1 Pro 64-bit, we went to Remote tab and enabled Remote Desktop.   We entered into the Remote Desktop Users group two users who are local on the box.  One of those is local admin and the other is a standard user.  When we connect
    to this machine by remote desktop and then authenticate, we get a message from Windows that the Remote Desktop Users group needs to be able to login through Remote Desktop Services.    
    I looked in secpol.msc and the Local Policies | User Rights Assignment | Allow logon through Remote Desktop Services already has the Remote Desktop Users included.
    What could be going wrong here that might cause Remote Desktop to disallow authenticated users that match to the Remote Desktop users group?
    Will

    Hi,
    Please check whether two machines are in the same network environment. And make sure if
    Remote Desktop Services is running, you can follow these steps:
    Press Windows + R keys simultaneously, type services.msc then press
    Enter.
    Check the status of Remote Desktop Services.
    Roger Lu
    TechNet Community Support

  • Accessing ASDM through MS Remote Desktop Services session based system

    I am setting up a MS Remote Desktop Services system for a client.  This is being configured as a jump server so everyone at the client will go through this system (aka jump server) to access systems via ssh, https, etc that are in a restricted part of the network.  I am running into a problem getting ASDM to work.  I can bring up the initial web page directly on the server via Internet Explorer, so that tells me I can get to the ASA.  I have installed Java 1.7.10 as this is the recommended version on looking at the Java site for Windows 2012.  When I try to install the dm_launcher, it says that Java isnt installed..
    Has anyone been able to get this to work ?
    Ron

    I've used ASDM fine from an RDS platform. I used Java 7 update 45. How are you trying to install the launcher?
    Sent from Cisco Technical Support iPad App

  • Windows Server 2008R2 running Remote Desktop Services reports printer process does not exist when installing PDF printer

     Windows Server 2008R2 running Remote Desktop Services reports printer process does not exist when installing PDF printer, And when Installing network printers from the domain controller it reports it cannot connect to printer.  I can ping all
    network devices. I can connect to the internet.
    On boot I get a netlogon 5719 error followed by service control manager errors 7023,7001 and a group policy error 1129.
    Clients can connect to the remote application and RDP operates to connect to the server internally and externally.
    The domain controller is another server 2008r2 box. I have scoured the internet but have not found any solutions that work yet.

    Hi,
    After referring to your post, it can be identified that the issue which you are facing is mostly due to some network issue in your environment. Please recheck your network connection issue between computer and domain controller. 
    Can you able to ping with IP address and also with fully qualified name of a domain controller in the users' and computers' domain. If it fails states that name resolution issue with computer and domain controller. Are you using MS DHCP Relay agent then there’s
    available Hotfix for the particular Event ID. Please go through this KB 2459530 to fix the error event ID.
    As per the net logon error 5719 which you are facing states that the client component of Netlogon was unable to locate a DC for the domain it was trying to perform an operation against. Below is one of the reason. If this is being logged on a DC and the event
    refers to the DC's own domain, something might be preventing the client component of Netlogon from starting a network session (to itself or to another DC in the domain). The following event 7001 & 7023 states start & stop operation service. Please
    go through beneath article for more details.
    1.  Event ID 5719 is logged when you start a computer
    2.  Netlogon 5719 and the Disappearing Domain [Controller]
    3.  Event ID 1129 — Microsoft-Windows-GroupPolicy
    Hope it helps!
    Regards.

  • How do I remote control a user in remote desktop services in Windows Server 2012?

    Hello,
    we currently operate in a 2008 R2 environment with the majority of clients connecting to our terminal servers.  We use the remote control feature in terminal services manager to connect to a users session when a user phones our helpdesk with
    a question / issue.
    Just today I've installed 2012 server on a hyper-v virtual machine to have a play with it.  I've installed the Remote Desktop Services and noticed this remote control feature is gone.  I can still log off or send a message to a user, but I can
    no longer remote control their session.
    I've seen one or two other posts stating this feature has been removed completely.
    So, a couple of questions:
    1. How on earth do I "shadow" or connect to a users session now?
    2. If I have to go third party to get this functionality back, what's the best software on the market for this and does it support remote connecting of users who have their RDP session span multiple monitors? (2008 R2 doesn't)
    3. Will Microsoft ever bring this feature back? as at this stage I doubt we would move to 2012.  This is the one feature that is crucial to the day-to-day running of our helpdesk.
    Cheers.

    A large percentage of our IT support business is through remote management. Most of our large enterprise customers are Terminal Server environment (now called Remote Desktop - why does Microsoft have to change EVERYTHING - how would they feel if I changed
    the colour of the sky from blue to red just because I could?).
    Last week, after much expense to the customer (and realising that there WOULD be some cosmetic headaches to contend with Server Management) we installed a new "Remote Desktop Server" for them and shifting them from 2003 - a big leap so we discovered.
    During deployment it came as a HORRIFIC surprise that we could not remote control user's sessions!
    Yes, we ARE to blame for not fully realising the cock-up Microsoft has made for us. We should have fully researched every detail of what changes they made and what they have robbed us of.
    Firstly, the removal of the ability to fully manage user's sessions came as a HUGE blow!
    The remaining multiple issues that followed (including the hugely cumbersome and SLOW way of accessing user's sessions and the false information that the console was reporting users logged in when they had already logged out) suddenly resulted in us decommissioning
    the new 2012 installation in favour of a 2008 R2 installation.
    Some may ask; Why not use "Third Party" apps to counteract the issue? Firstly; why spend MORE and why use a third party app that "is as" cumbersome to use just because of a freaking feature that Microsoft deemed a "security risk" - for G.D sake!
    We have now been directed by management to convince customers that a move to 2012 is NOT recommended - good choice boss, I love you!
    The question is; will Microsoft re-implement this feature and fix Server Management performance/accessibility in a future release before 2008 R2 is no longer available? Probably not - it looks like their stubbornness to forge ahead with their craze mind-set
    of transforming their products into something that is now annoying millions (including their bloody push towards everything-cloud which NONE of our customers want anything to do with).
    Microsoft! Get us back on to your side and take a step back, take a deep breath and listen to consumers!

  • Questions in regards to server 2012R2 Remote desktop Service deployment and GPO

    Hi Everyone
    We have a business requirement moving to 2012R2 RDSH server. I have installed a 2012R2 member servers and enabled Remote desktop licensing role. I have activated the licenses. the servers is in operational
    I have deployed 3 windows 2012R2 member server "RDS1" , "RDS2" and "RDS3".
    on RDS1 I ran Add roles and Feature Wizard > Remote Desktop Services installation > Quick Start >Session based desktop deployment to complete the installation.
    On RDS1 Server Manage Dashboard Page Select Remote Desktop Services > Overview. Under RD Licensing I added my 2012R2 license server "2012r2-tslic". Go to task. Edit deployment properties RD license mode to per device and click OK.
    Reboot RDS1
    Check RD Licensing Diagnoser everything is clear
    On RDS2 I did the exact same thing ran Add roles and Feature Wizard > Remote Desktop Services installation > Quick Start >Session based desktop deployment to complete the installation. 
    But With RDS2 I move this server to an OU that link to a GPO with RD licensing details. after reboot the servers check RD Licensing Diagnoser I can see 2012r2-tslic specified as the license servers.  
    Based on this document
    http://blogs.technet.com/b/askperf/archive/2013/09/20/rd-licensing-configuration-on-windows-server-2012.aspx  Are you suppose to configure RD license server via Remote desktop Service deployment ? Not GPO ?
    Here are my questions
    We currently have ten 2008r2 terminal servers in a NLB cluster. each RDSH server have in house application installed on each one of them. User connect to the 2008R2 RDSH servers via RDP connection. we have a restricted GPO apply to those
    RDSH servers. user cannot do anything on RDSH servers apart from running the application and use excel.  On the remote desktop session host configuration we have enable settings like end a disconnected session , Active session limit  ,
    remote control users session , LPT port redirection.
    We push out RD license server detail via GPO to the terminal servers
    Can I use our existing GPO apply the licensing server settings , desktop restriction setting to the 2012R2 RDHS servers or we should be using Remote desktop Service deployment to do the job ? If that is the case how would you transfer the
    current 2008r2 environment to 2012 using Remote desktop Service deployment. is that mean I have to manually configure 1 by 1.
    Please help
    Many thanks

    Hi,
    Please see my response to you in the other thread.  Please contact me via email and I will go over the basic planning and deployment steps with you which will help clear things up and get you started off on the right foot.
    You should only run through the wizard and create a RDS deployment once.  Then you add the various servers (RDSH, RD Licensing, RD Gateway, etc), set Deployment properties, etc.
    Thanks.
    -TP

  • Terminal Services (TS) or Remote Desktop Services (RDS) scenario clarifications

    Dear Support,
    Question:
    Do I still need to purchase RDS CALS license? or can use MSDN CALs in the Terminal Server?
    Due to MSDN subscribers are End users, do not use Production Data and have to demo their developed applications to other End users group.
    Scenario:
    1. Use only Remote Desktop Session.
    2. End users are MSDN Subscribers.  (Although stated by Microsoft End users are non MSDN subscribers)
    3. End users demo applications to End users.
    4. End users develop their applications and have to demo to other End users group.
    From MSDN link:
    Client Access Licenses for Terminal Services
    With an MSDN subscription, you are allowed to provide end users access to Internet demonstrations of your programs via Terminal Services (Windows Server 2003 or Windows Server 2008) or Remote Desktop Services (Windows Server 2008 R2). Up to 200 anonymous
    users can simultaneously access your demonstration this way. Your demonstration must not use production data. MSDN subscribers are licensed to demonstrate their applications to end users,
    but Terminal Services (TS) or Remote Desktop Services (RDS) is the only scenario where end users without an MSDN subscription can interact with the demonstration application while the software is licensed through MSDN subscriptions.
    Accessing CALs            
    MSDN subscribers can access CALs for demonstration purposes through the
    Product keys page of MSDN Subscriber Downloads. Please access the documentation resources online for assistance with the
    Terminal Server activation process. If you have any questions, please visit the Microsoft
    Terminal Services forum.
    Mary Lee

    Hi
    Please call the licensing to be sure. In the USA (866) 230-0560 or
    [email protected]
    Regards, Philippe
    Don't forget to mark as answer or vote as helpful to help identify good information. ( linkedin endorsement never hurt too :o) )
    Answer an interesting question ? Create a
    wiki article about it!

  • I want to be able to print using windows remote desktop services what printers can i use?

    Hi I want to use Windows Remote Desktop Services on my iMAC.
    I understand some printers work but some dont  when printing from the VDI client.
    Can anyone give me a list of printers that will work with the VDI client or some work arounds so that I can print using my iMAC and that print jobs can be parsed through the VDI clien to my iMAC and then printed through the iMACs connection to the printer
    Thankyou

    ARD won't be as smooth as you think  over the Internet and be a security risk for your daughter.
    Your best bet would be to install nannyware, then when she's asleep you can review the logs.
    This is the best and Mac friendly
    http://www.internetsafety.com/

  • AWS Remote Desktop Services Licensing

    Greetings! This is my first to post, so please bear with me.
    Here is my scenario:
    My company has a number of Windows servers (company-owned hardware & OS licenses) in a server farm. My company has purchased User & RDS User CALs for all employees to be able to RDP into each server. Server licenses & CALs are all retail purchases,
    no Volume Licensing, no Software Assurance.
    The company has also purchased a VL w/SA Microsoft Office w/100 seats. I have installed Office on our servers for our users' use. 
    I know this configuration is compliant with Microsoft's License Agreements as we own the hardware and directly purchased the licenses.
    However, in addition to the server farm, my company has an account with AWS and wants to create several multi-user (via RDP) servers. Also, my company wants to install Office on the servers for our users.
    Here is my problem:
    I cannot find clear concise documentation from either Microsoft or AWS confirming the licensing requirements for my AWS scenario.
    I've found many blogs saying one could use the regular User/RDS User CALs purchased via VL or Retail.
    Alternately, I've found several other blogs talking about User/RDS User SALs (Subscriber Access Licenses) as the requirement since Windows is licensed from Microsoft via AWS through SPLA (Subscriber Provider License Agreement). 
    Are SALs included in my monthly payments to AWS? Where do I buy SALs? Does anyone have official documentation from AWS on this topic? The software vendor from which I purchased my company's VL Office has never heard of SALs.
    Additionally, I have not been able to find clear documentation regarding the use of Office on an AWS Windows instance. I know AWS supports LM (Licensing Mobility) for users with certain Volume Licensing agreements but LM only applies to Server Applications.
    Microsoft Office is a desktop application.
    Where can I buy Office for AWS instances? How do I license my users to be able to use Office on an AWS instance?
    I've contacted Microsoft and was redirected to AWS. I've contacted AWS but no one seems to know the answers. Is no one else asking these questions? Is no one else using AWS Windows-based servers in a multi-user environment over RDP?
    Any input on this topic would be very much appreciated.

    I'm doing some licensing audits now and the only thing I've found was a webinar by AWS dated February 27, 2012, so I don't know if it's still the most current information. Due to the fact that the Windows Server license is being offered through Amazon
    you would need a SAL in order to legitimately use any Remote Desktop Services, once you buy a SAL any existing user CALs you already have are now valid in AWS. The presenter goes on to say that Amazon would really like to offer SALs, BUT, unfortunately they
    do not. This then lead me to alternating paranoid speculation that Microsoft has put Amazons request to sell SALs into the nearest round file so that Azure would be more attractive and a superiority complex rampant with bitter hatred for Amazon's inability
    to make money that they would really like to make.
    There were a couple of things that seemed kind of odd about this to me. Any existing Server CALs you have are "instantly valid" for use in AWS, but you're RDS CALs are not. It seems to me since the non technical use of those licenses are nearly identical
    they should either both be valid or both be invalid for AWS use, so I guess this puts one more point in the hooray Microsoft column.
    Apparently I can't post links yet, but there is a page with some references to License Mobility in AWS and a link to the webinar at the bottom in the Licensing & Costs section. The page is aws dot amazon dot com slash Microsoft and the remarks regarding
    the RDS licensing are at the 15 minute mark of the webinar. Overall the webinar was generally more useful and less marketing than the page it's on, so if you plan to do anything with SharePoint, SQL Server or any other products it would be worth watching.
    Also, Amazon says there is no way to run any version of Microsoft Office in an AWS instance legally, maybe you could get by with Open Office? If you do find a way to run any RDS applications in AWS legally I would be interested to hear about how.

  • AD user account Remote Desktop Services Profile tab

    I have a template I created for a RDS environment.  I'm using the AD account properties to map the Home directory.
    If I set the home folder on the "Profile" tab and copy the template to a new user, it works just fine.  If I change the template to connect the Home folder from the Remote Desktop Service Profile tab it works for the template...but when I
    copy that template to a new user the home folder attribute does not copy.
    Anyone know why?  Or perhaps of a trick to get this to work?
    I've gone as far to set the msTSHomeDrive and msTSHomeDirectory attributes "Attribute is copied when duplicating a user" but doesn't appear to work.  I dont' see an updated "RDS" type attribute that stands out on this 2012 DC.

    Hi,
    Please go through below article might helpful in your case.
    How to read msTSProfilePath, msTSHomeDrive and msTSHomeDirectory properties from AD (VB.NET)
    http://blogs.msdn.com/b/alejacma/archive/2010/10/13/how-to-read-mstsprofilepath-mstshomedrive-and-mstshomedirectory-properties-from-ad-vb-net.aspx
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • To install Remote Desktop Services User CAL on Windows Server 2008 R2 Enterprise Edition with SP1

    Dear Sir,
    Presently we have installed Windows Server 2008 R2 Enterprise Edition with SP 1. And now i would like to install Remote Desktop Services User CAL on this server. I have 25 digit product key of Windows Server
    2008 R2 Remote Desktop Services User CAL (20). Downloaded this product key from our MSDN Subscriptions.
    Kindly suggest me how to install (CAL server with product key that i have) and configure remote desktop services on my above existing server also how to point other server with my CAL server.
    Thanks

    Hi,
    1. Install Remote Desktop Session Host and Remote Desktop Licensing Role Services using Server Manager.
    2. Open RD Licensing Manager (licmgr.exe), Activate your server, then install your license
    3. In RD Session Host Configuration (tsconfig.msc), set the Licensing mode to Per User and Specify your RD Licensing server name (itself).  If you want you may configure these two settings via group policy setting instead.  The path of the
    group policy settings is Computer Configuration\ Administrative Templates\ Windows Components\ Remote Desktop Services\ Remote Desktop Session Host\ Licensing
    4. You may point other RDSH servers to your RD Licensing server using RD Session Host Configuration or via group policy as mentioned above.
    5. Optionally you may consider installing other Remote Desktop Role Services such as RD Gateway, RD Web Access, RD Connection Broker, etc.
    -TP

  • How to install the Remote Desktop Services role on a Windows 2012 R2 Server

    Hello,
    I am a bit confused on how to install the RDP role on a 2012 R2 server. I have a two server domain and would like to make the second member server an RDP server to host applications (Word, Excel, a medical software, etc.) where users from their windows
    7 desktop will use the Remote Desktop Connection to connect to the server, create a session and do their work. When installing the role, I am prompted with two options:
    1- Role-based or feature based installation
    2- Remote Desktop services installation
    I see the RDP install option in both cases.
    1- Which one do I use?
    2- What role services do I install? (Connection broker, Gateway, Licensing, Session Host, Virtualization host and Web access). I think I need the first four only.
    3- When installing software after RDP, I use the Change user /install and Change user /execute commands. What happens to the software that is already installed? Can remote
    users use those?
    Any help will be very much appreciated.
    Thank You,
    Victor.

    TP,
    Thank you for your response. I added the RD Licensing thru the Role-based option.
    Also opened the local group policy thru gpedit.msc and added the server name and the licensing mode type to Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session
    Host -> Licensing
    Use the specified RD license servers = NameOfMyServer
    Set the Remote Desktop licensing mode = TypeOfMyLicense (Per User in my case)
    Thank you again,
    Victor

  • Remote Desktop Services Role on a Virtual Machine (VM) Requirements

    Does MS recommend installing RDS Role on Hardware or Virtual Machine? I have a use case where I have about 35 people that will be using the Internet Explorer and possibly run additional piece of software. I'm having trouble determining if the RDS Role on
    Virtual Machine will be able to sustain the load of so many users. Should the same performance metric used in hardware selection be appropriate to apply for Virtual Machines. We are using VMware on pretty powerful DELL hardware, which is also hosting
    120 existing VMs as of now. So my questions is would VM with 4 CPU's, 8GB of RAM, 80 GB Virtual Disk and 1 GBPs NIC would be handle the job?

    Hi,
    Thank you for posting in Windows Server Forum.
    There is no any particular requirement to run RDS on physical or virtual machine. But if you want to install RD Virtulization role then you need to see that Hyper- V role installed because “when the RD Virtualization Host role service is installed, Server
    Manager checks to see if Hyper-V is installed. If Hyper-V is not installed, Server Manager will install it”. And Hyper-V role cannot be installed on virtual machine so for that you need to install on Physical machine. Other all RDS role can be installed
    on virtual machine also.
    Install the Remote Desktop Virtualization Host Role Service
    In addition, please check below articles.
    1. Remote Desktop Services: Server and client requirements
    2. RDS Hardware Sizing and Capacity Planning Guidance.
    Hope it helps!
    Thanks,
    Dharmesh

Maybe you are looking for

  • F.05 fx.val. and archived documents

    Hello, It is possible that with the fx. valuation with F.05 tr. (end month closing), also works with archived documents, (XARCH field)? I mean, I have Archiving in the company and there are differences betwen BSEG and BKPF archived documents and the

  • Getting missing method error - first attempt at arrays

    I'm trying to work with arrays for the first time ever - I understand the concept, but can't quite get the syntax down. Here is the class which won't compile and is giving me a missing method body or declare abstract message - please help me understa

  • The left speaker has lower volume than the right speaker of my pavilion g4-1202ax..

    please help me with this problem.. the left speaker has low volume.. but the balance is equal.. what should i do?? is any one there wants to help me?? 

  • Hic-cup when shutting down

    A recent change which worries me somewhat. I usually wait for the computer to shut down using the message "if you do nothing your computer will shutdown in 2 mins, 1min 59..." Until recently, when the 2 minutes were up the screen went black and then

  • Help hooking up my Sony KDS-60A2000

    I just bought a Sony KDS-60A2000 hd television. I have a Belkin cable to hook my Mini to the HDMI input on the Sony. I hooked everything up and the Mini came up on the Sony. The picture then became gradually snowy then went black. I have been unable