Search This Blog

Tuesday 24 October 2017

To sing in remotely, you need the right to sign in through Remote Desktop Services

After the server  has been promoted to a domain controllar, when trying to open Local Users and Gropus (lusrmgr.msc) console, it returns the following error:

The computer xxx is a domain controllar. This snip- in cannot be used on a domain controllar. Domain account are managed with the Active Directory Users and Computers snap-in.































To allow connection to the domain controllar member to the Remote Desktop users group you need to:
  • Start local policy editor (gpedit.msc).
  • Go to Computer ConfigurationàWindows SettingsàSecurity SettingsàLocal Policiesà User Right Assignment.
  • Find the Policy Allow log on through Remote Desktop Services.






















  • Edit the Policy by adding the local group Remote Desktop Users (like this: Domain Name\Remote Desktop Users), a `domain user, or a group (like this: domain\some group name) to it.






















  • Run the update of the local policy in command prompt.
  • Gpupdate /force
  • Reconnect RDP.

No comments:

Post a Comment