Windows Server 2019 not authenticating based on User Group

Dan 1 Reputation point
2024-03-04T19:17:23.4733333+00:00

Hi,

I have a Windows 2019 Standard file server, domain member (not the DC), to which I'd like 2 non-Admin user to be able to remote to.

I set up a Group in Active Directory, let's call it AllowRemote, and added these 2 non-Admin users to that group.

I then went into the Remote settings on the server, System Properties > Remote tab > Select users, and added the AllowRemote group. In other words, users who are members of AllowRemote are allowed to remote in, users who are not members are not allowed in.

This works inconsistently. It will work for one user but not for another user.

If I add a user explicitly by username, it works. But I'd prefer to control this by group membership.

How would I go about troubleshooting this to see what's going on behind the scenes?

Thanks.

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,505 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,746 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Marcin Policht 13,480 Reputation points MVP
    2024-03-04T19:28:33.66+00:00

    Add both users to the built-in Remote Desktop Users group instead (directly or indirectly)


    hth

    Marcin


  2. Daisy Zhou 19,271 Reputation points Microsoft Vendor
    2024-03-05T02:02:57.59+00:00

    Hello Dan,

    Thank you for posting in Q&A forum.

    Hope the information provided by Marcin Policht is helpful.

    Is the problem resolved? If no, you can try to troubleshoot the issue as below:

    1.Based on the description "This works inconsistently. It will work for one user but not for another user.", what error message do you receive when the other user can not log on remotely?

    2.Please check if the 2 non-Admin users are only in this AllowRemote group and not in the other group.

    3.Please check if this AllowRemote group is not in other AD groups.

    For both point 2 and point 3, if the 2 non-Admin users are also in other AD groups (such as G1) except this AllowRemote group, and / or if this AllowRemote group is also in other AD groups (such as G2) , please check G1 and G2 are not denied to logon this server remotely.

    4.Please check the user is not set to log on to specific domain machines on user Properties.
    User's image

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments