locked
Remote desktop failing for any user other than administrator RRS feed

  • Question

  • I can access the whs desktop remotely if I sign in as administrator but I can't access it when signing in as any other user.  The error message is "To log on to this remote computer, you must be granted the Allow log on through terminal services right.  By default members of the Remote Desktop Users group have this right..."

    I have checked "Enable remote access for this user" and the user is a member of the Remote Desktop Users group.  What am I missing?
    Tuesday, April 7, 2009 4:25 PM

Answers

  • You shouldn't grant anyone except the Administrator account access to your server's desktop. 
    A) it's unsupported (as is Remote Desktop access to your server in general).
    B) It represents a significant security issue; by default a user who can access the server desktop has fairly wide powers on the sever, and can use tools that could cause damage to the server.
    C) Any user who can log in to the server using Remote Desktop is prohibited from logging in to the Remote Access web site.

    I'm not on the WHS team, I just post a lot. :)
    Tuesday, April 7, 2009 4:38 PM
    Moderator

All replies

  • You shouldn't grant anyone except the Administrator account access to your server's desktop. 
    A) it's unsupported (as is Remote Desktop access to your server in general).
    B) It represents a significant security issue; by default a user who can access the server desktop has fairly wide powers on the sever, and can use tools that could cause damage to the server.
    C) Any user who can log in to the server using Remote Desktop is prohibited from logging in to the Remote Access web site.

    I'm not on the WHS team, I just post a lot. :)
    Tuesday, April 7, 2009 4:38 PM
    Moderator
  • I can access the whs desktop remotely if I sign in as administrator but I can't access it when signing in as any other user.  The error message is "To log on to this remote computer, you must be granted the Allow log on through terminal services right.  By default members of the Remote Desktop Users group have this right..."

    I have checked "Enable remote access for this user" and the user is a member of the Remote Desktop Users group.  What am I missing?

    I think you'll have to fiddle with the "Allow log on through terminal services" setting; Run gpedit.msc and add "'Remote Desktop Users" in "Local Computer.../Computer conf.../Windows Settings/Security Settings/Local Policies/User Rights Assignment/...".
    I'm not 100% sure, but I think that's how I solved login for other than Administrator.
    Of course this is yet another page in the ridiculously thick book of Stuff not supported in Microsoft Home "server" :)
    This message is shareware - Please register!
    Saturday, April 11, 2009 6:47 AM