Event ID 73 — Remote Desktop License Server Security Group Configuration

Applies To: Windows Server 2008 R2

When the Remote Desktop Licensing role service is installed on the server, the Terminal Server Computers local group is created. The license server will respond only to requests for RDS CALs from Remote Desktop Session Host servers whose computer accounts are members of this group if the Computer Configuration\Administrative Templates\Windows Components\Remote Desktop Services\RD Licensing\License server security group Group Policy setting has been enabled and applied to the license server. By default, the Terminal Server Computers local group is empty.

When the Remote Desktop Licensing role service is removed from the server, the Terminal Server Computers local group is deleted.

Event Details

Product: Windows Operating System
ID: 73
Source: Microsoft-Windows-TerminalServices-Licensing
Version: 6.1
Symbolic Name: TLS_E_LS_REMOVE_LOCALGROUP
Message: The Terminal Server Computers local group cannot be deleted.
Win32 error code: %1!s!

Resolve

Delete the Terminal Server Computers local group on the license server

To resolve this issue, delete the Terminal Server Computers local group on the Remote Desktop license server. If the Remote Desktop Licensing role service is no longer installed on the server, the Terminal Server Computers local group is no longer needed.

To perform this procedure, you must have membership in the local Administrators group, or you must have been delegated the appropriate authority.

To delete the Terminal Server Computers group:

  1. On the license server, open the Local Users and Groups snap-in. To open Local Users and Groups, click Start, click Run, type lusrmgr.msc, and then click OK.
  2. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Yes.
  3. In the left pane, click Groups.
  4. In the right pane, right-click Terminal Server Computers, click Delete, and then click Yes.

Note:  If the license server is installed on an Active Directory domain controller, use the Active Directory Users and Computers snap-in (dsa.msc) to delete the Terminal Server Computers group. To delete the Terminal Server Computers group on a domain controller, you must have membership in the Domain Admins group in AD DS, or you must have been delegated the appropriate authority. To open Active Directory Users and Computers, click Start, click Run, type dsa.msc, and then click OK.

Verify

To verify that the Terminal Server Computers local group is correctly configured on the license server, use the Local Users and Groups snap-in.

Note: If the license server is installed on an Active Directory domain controller, use the Active Directory Users and Computers snap-in to verify that the Terminal Server Computers group is properly configured. To use Active Directory Users and Computers on a domain controller, you must have membership in the Domain Admins group in AD DS, or you must have been delegated the appropriate authority. To open Active Directory Users and Computers, click Start, click Run, type dsa.msc, and then click OK.

To perform this procedure, you must have membership in the local Administrators group, or you must have been delegated the appropriate authority.

To verify that the Terminal Server Computers group is properly configured:

  1. On the license server, open the Local Users and Groups snap-in. To open Local Users and Groups, click Start, click Run, type lusrmgr.msc, and then click OK.
  2. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Yes.
  3. In the left pane, click Groups.
  4. In the right pane, the Terminal Server Computers group should be listed. If the License Server security group Group Policy setting is enabled for the license server, the group should contain a list of computer accounts for Remote Desktop Session Host servers.

Note: If the Remote Desktop Licensing role service has been removed from the server, the Terminal Server Computers local group should not be listed.

Remote Desktop License Server Security Group Configuration

Remote Desktop Services