Administrative/RDP Roles on a RODC
i've got tech needs added administrator , have rdp rights on read-only domain controller in remote site. here's constraints , i've tried far:
they can't domain admin.
they can't have admin , rdp privs on of our other 4 dc's - took user delegation dc ou out of picture understand.
i tried dsmgmt.exe , added user local admin , rdp role, still can't remote server.
(followed kb dsmgmt - http://technet.microsoft.com/en-us/library/cc732301(ws.10).aspx)
the group user in added via gpo in remote desktop users in system control panel snap-in.
added domain admins , user security group , set group in 'managed by' tab under rodc's ad object.
any other thoughts? thought on when found dsmgmt utility, missing other adding user each role?
thanks , big cookie goes out can help.
hi,
open gpedit.msc on rodc, or create gpo rodc, add user following policies:
computer configuration\policies\windows settings\security settings\local policies\user rights assignment\allow log on through ts.
can assign other rights users here.
thanks.
this posting provided "as is" no warranties, , confers no rights.
open gpedit.msc on rodc, or create gpo rodc, add user following policies:
computer configuration\policies\windows settings\security settings\local policies\user rights assignment\allow log on through ts.
can assign other rights users here.
thanks.
this posting provided "as is" no warranties, , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment