Logon denial.........TS App

  • Thread starter Thread starter Momo
  • Start date Start date
M

Momo

I've currently setup TS in App mode and configured all the required
settings according to our network requirements. This is a Win2k3
Server.

We initially tested a Win2k and everything worked fine. Now we are
using a Win2k3 with a similar settings. The problem is the TS allows
unlimited number of Administrators to logon but it doesn't allow
standard users which belong to a local group we have defined as
Terminal Users(which contains a security group for AD).

We have configured the permissions in TS COnnections and also
configured the locall policy to Allow Local Logon and Allow Logon
through TS to this group. But when the users try to logon it gives the
message "TS has exceeded the max no. of allowed connections".

Whats strange is if we add the members from Terminal Users into the
Local admin grp all of them can logon.

Initially we though this had s/thing to do with the local GPO but after
checking the settings all seems correct...so were completely
stunned.....

Any help would be appreciated......
 
1. Users do NOT require the Logon Locally right, as they did in 2000, except
when the TS is also a Domain Controller (not recommended).

2. Users (or a group they are a member of) should be members of the local
"Remote Desktop Users" group.

3. The local Romote Desktop Users group should have guest & user permissions
to the RDP-Tcp connection in the Terminal Services Configuration (or in Group
Policy)

4. In 2003 TS, the TSLS must be running on a 2003 Member Server or DC in
the same Domain as the TS.

5. Make sure the TS is in the same licensing mode as licenses you have
activated on your TSLS.

6. Check the event log on the TS for the reason why users are being denied
logons.

Patrick Rouse
Microsoft MVP - Terminal Server
http://www.workthin.com
 
Back
Top