8
3
I am trying to use Remote Desktop to another PC on our domain. If I use an administrators account this works fine, however when I use a normal user it gives the error:
The connection was denied because the user account is not authorised for remote login.
As per these questions I have:
- Set "Allow Log on through Remote Desktop Services" (adding the Remote Desktop Users group).
- Added the user to the remote desktop services group
- Set "Allow users to connect remotely by using Remote Desktop Services"
- Done
gpupdate /force
several times on the RD host machine
If I go in to Remote Settings > Select Users on RD host and add the domain user "walter.white" that user can then login to the machine from the other PC.
I don't want to have to do that on every machine. I want to set it by GP object which I thought would be "Allow Log on through Remote Desktop Services" - as you can see above this group doesn't appear in this dialog (and I guess is the cause of the issue).
I know the GP has taken effect as if run "secpol.msc" and look at "Allow logon through Remote Desktop Services", I do see Remote Desktop Services (as well as Walter White which I added to the GP object).
We have Windows Server 2012.
Did you also apply the Restricted Group changes via GP (as laid out in the last link you provided)? – Ƭᴇcʜιᴇ007 – 2017-02-14T16:07:22.917
@Ƭᴇcʜιᴇ007 I may be being stupid but I can't see anything about "Restrictive Groups" in any of those links (and I've tried CNTRL+F on the page!) – tim.baker – 2017-02-15T13:55:35.540