Administrative/RDP Roles on a RODC


i've got tech needs added administrator , have rdp rights on read-only domain controller in remote site. here's constraints , i've tried far:

they can't domain admin.
they can't have admin , rdp privs on of our other 4 dc's - took user delegation dc ou out of picture understand.
i tried dsmgmt.exe , added user local admin , rdp role, still can't remote server.
     (followed kb dsmgmt - http://technet.microsoft.com/en-us/library/cc732301(ws.10).aspx)
the group user in added via gpo in remote desktop users in system control panel snap-in.
added domain admins , user security group , set group in 'managed by' tab under rodc's ad object.

any other thoughts? thought on when found dsmgmt utility, missing other adding user each role?

thanks , big cookie goes out can help.

hi,

open gpedit.msc on rodc, or create gpo rodc, add user following policies:

computer configuration\policies\windows settings\security settings\local policies\user rights assignment\allow log on through ts.

can assign other rights users here.

thanks.

this posting provided "as is" no warranties, , confers no rights.


Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group