[TriLUG] Windows / Active Directory help needed

John Berninger john at ncphotography.com
Wed Jun 10 10:45:42 EDT 2009


Apologies in advance for any duplicates as a result of cross-posting to 
internetworkers and trilug.

I'm a Linux guy, and I'm having to figure out how to make AD in Win2k3 
work.  So far, I've gotten far enough to have the domain up and running, 
users are being authenticated properly, I can add computers to the 
domain, etc...

What I can't do is figure out how to allow a given user (let's call the 
user "joe") to RDP into a member server without giving joe Domain Admin 
rights.  I have added joe to the Remote Desktop Users group in AD 
(DOMAIN/Builtin), I have moved the computer to a new OU and given that 
OU a Group Policy that gives Remote Desktop Operators the following privs:
- Allow log on on Locally
- Access this computer from the network
- Allow log on through Terminal Services

What am I missing?

-- 
John

Dovei'andi se tovya sagain.




More information about the TriLUG mailing list