I was facing a little situation this week. We do have Terminal Servers (TS) with TS licensing server (TSLS) and it works fine, all the settings have been configured properly to let users I have to access it from outside and so on.
But I wanted to enable it for users to access Windows XP boxes (WinXP) , their WinXP from another location (the gateway). And I thought enabling RD and allow access to their Desktop would be less tricky.
First I created a GPO with 2 things:
1. Allow Users to connect remotely using TS from Computer>Adm template>Windows Components/Terminal Services>
2. Set the permisson to the right groups for log on from Computer>Windows settings>Local Policies>User Rights Assignment
But no this did not too much and gave me a nice error message when trying to log on when login with authorized usres: you do not have access to logon this session.
This meant that users can do TS on the WinXPs but cannot logon.
So if you want to avoid this little embarrassment please follow those steps (III being my mistake)
Read full post...