account not authorized for remote login??


i found previous posts , info on other web sites error get, far nothing helped me solve it.

what i'm trying quite straightforward -- thought: have 'top level' domain number of subdomains. want create "subdomain administrators" group of users must have administrative rights on subdomains, *without* giving them more ordinary user rights on top level domain.

the domains involved server 2008 r2 ad level. both servers server 2008 r2 sp1 standard clean installs, both activated and fully date windows updates before dcpromo-ed.

let's call top level domain "dom.local" , first subdomain "sub.dom.local" (all names generalized replacements here on).

i created new 'universal' security group called 'subadmins' in dom.local.

i created 2 user accounts in dom.local,

  • one member of "domain users" , of "enterprise admins",
  • the other member of "domain users" , of subadmins.

then went sub.dom.local dc.

there, in builtin\administrators group, found enterprise admins group from dom.local present, expected.  i added subadmins group from dom.local list.

now tried log on the sub.dom.local dc rdp (from win7 client member of neither domain, using stored credentials). works fine user member of enterprise admins, refuses work 1 that's in subadmins.
error "the connection denied because user account not authorized remote login".

but when i add same user directly sub.dom.local administrators group, works fine. remove him again, stops working.

i deleted the subadmins group, created new 1 (with name), added user it, added sub.dom.local builtin\administrators group: same. works when user added directly, can't log on if added via group.

help?

 


edit: a few things tried didn't help, didn't mention when posted question:

  • add subadmins group 'rdp users' builtin group on sub.domain.local (and other builtin groups, same lack of effect)
  • add subadmins group 'access computer network' security setting in domain controller security policy of sub.domain.local (because it's dc trying log on to) , ran gpupdate.

 



it must have been replication issue, morning worked without further changes.

yet had run repadmin /syncall on top level dc yesterday, , didn't then.

 



Windows Server  >  Security



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...