Domain user remotely access his desktop via RDP


Recommended Posts

Hi

How can I let a domain user ?John Allen? from his home to access his desktop (WS-A) at work via RDP.

First he would access his work network ( environment Active Directory 2003

) via VPN and then how can I let him to access his desktop (not the server) at work via RDP ??

Could someone post step by step how should I configure that ? Is it through server local policy (gpedit.msc) or domain policy (gpmc.msc ) or something else ? I have got only one server which is AD as well

Remote Desktop is enabled on WS-A.

I tried to google for it by using this key :

? add user to remote desktop groups Active Directory ? but I could not get what I am looking for :

http://www.google.com.au/search?hl=en&...mp;aq=f&oq=

http://www.computing.net/answers/windows-2...stion/5604.html

Thanks

Hey Zillah

Do you know if the firewall that he vpn's onto allows RDP into the business? You shouldn't need to make any changes in active directory unless want to take away the hassle of going to each computer to enable remote desktop

There is a good chance that the inbound connection is being blocked by the firewall

Hi Silver_Guy

What I did for testing purpose , I can vpn to the work's network with account that has previlidge for VPN as well John Allen he can vpn to the work's network.

Then I can RDP to (WS-A ,,,,,John Allen's PC) with local admin account not John Allen account.

That means if there is firewall preventing VPN connection it would have denied local admin account from logging in ,,,,,wouldn't it ?

Thanks

  Quote
On the WS-A Copmuter - Right Click Computer - Manage - Local Users and Groups - Groups - Remote Desktop Users

I can not do that because user is not locally created it is a domain user ,,,therefore if you search him on local PC you won't be able to find him.

  zillah2004 said:
I can not do that because user is not locally created it is a domain user ,,,therefore if you search him on local PC you won't be able to find him.

Try it. You can add domain users to the local workstation groups. Just use DOMAIN\USERNAME syntax, or when the search box comes up, click the locations button and select Entire Directory.

did you login to the domain or just the local computer because if you logged into the domain it should show the domain in the list

also on the select users screen you can type in the username "domain\username" and it should take it.

rdpp.th.jpg

  Quote
did you login to the domain or just the local computer

Since i am not at work now,,,what I did I vpn to the work network then I RDP to WS-A (192.168.0.10) then I logged in to this workstation (used by Allen John) as a domain admin (not local admin), although I tried local admin as well.

But I could not see any domain users ,,,,I do not what mistake I am doing.

Thanks

when you are at the login screen on WS-A use the domain admin account. in the format DOMAIN\USERNAME you will then be logging into the domain on that computer with your admin account you should then be able to see the domain listed in the location box

  Quote
when you are at the login screen on WS-A use the domain admin account. in the format DOMAIN\USERNAME you will then be logging into the domain on that computer with your admin account you should then be able to see the domain listed in the location box

I tried that same thing

  Quote
when you are at the login screen on WS-A use the domain admin account. in the format DOMAIN\USERNAME you will then be logging into the domain on that computer with your admin account you should then be able to see the domain listed in the location box

Do you thing because you are doing that locally and I am doing it through VPN ??

I have to try locally to log in to WS-A as a domain admin not a local admin and see if I can add John Allen.

Meanwhile could you please try to log in as a local admin and then try to use VPN and see if you are facing same my problem

Thanks

  zillah2004 said:
Do you thing because you are doing that locally and I am doing it through VPN ??

I have to try locally to log in to WS-A as a domain admin not a local admin and see if I can add John Allen.

Meanwhile could you please try to log in as a local admin and then try to use VPN and see if you are facing same my problem

Thanks

Alrighty Zillah you have a couple issues not being talked about here.

1.) IF the person is connecting through VPN, it does NOT matter if their "home" computer (from where the client is accessing) is on the domain because the RDP protocol uses a port, 3389, which should be open on the VNC side.

2.) On the computer the person is trying to remote into (at work), that person (if it is THEIR computer and on your domain) always has access and can be viewed at the "Remote Desktop" area for "Select Remote Users" (Mine is "mydomain\victor"

3.) If a firewall is on, then you need to open the ports which you can do by creating a GPO on the server level, and making 3389 open on the localsubnet.

I've read what you've wrote, and I am VERY VERY confused by what you are trying to say. If you want them to authenticate with your domain WHILE they log in at home, you'd need some type of VPN service like Cisco's software to establish a VPN connection and then their home computer would have to be put on the domain.

Please check these settings and reply back:

- When you try and access RDP, are you making sure the Username is "Yourdomain\John Allen"? Sometimes when you RDP the "Log Onto" will be set for the LOCAL account, and not your domain.

- Go into your CMD prompt and do "ping -a 127.0.0.1" and the computer name should be "ws-a.yourdomain.local" correct?

- On the server level do a gpmc.sc or gpedit.msc (i always use gpmc.msc) and on your default policy navigate to "Computer Config - Administrative Templates - Network Connection - Windows Firewall - Domain Profile.

Here you can enable and define "Allow Remote Desktop Exception" If your VPN and local IP scheme are the same, then you can just do "Allow unsolicited incoming messages from" and add localsubnet (but if your VPN and LAN are different IP schemes, the VPN'd person will NOT be able to access their computer via RDP)

Edited by Unholee

Thanks

  Quote
When you try and access RDP, are you making sure the Username is "Yourdomain\John Allen"?

I have got this screen locally and via VPN :

User name : support,,,,,,,,,,,,,,,,,,,,,,,,,,member of the domain admin group,,,,,if I write username like this "AML\support" , (Log on to) option will gray out.

Password : forum

Log on to : AML,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,This is my domain name at work,,,,,drop down menu there is another option if I want to login to "This computer"

  Quote
Sometimes when you RDP the "Log Onto" will be set for the LOCAL account, and not your domain.

For sure this is not the case , and If this is case you can not login unless John Allen user was created locally on WS-A, and since John Allen was created as domain user I can not login.

Even with the username "support" memeber of the domain admin I can not login to WS-A if "Log On to" is set for the LOCAL account.

I can access this WS-A as domain admin user locally and via VPN (that means I do not have an issue with Firewall , with port , exception,,,,,,etc),,,,,,,,,,now at this stage leave domain user (Allen John) aside,,,,,,why cann't I add a domain user on WS-A to "Remote Desktop Users" on WS-A ???????

To add a domain user to "Remote Desktop Users" on any workstation do I need to configure any thing on the server ?

After that I can troubleshoot in case if Allen John can not get connected remotely to his workstation

How much of this are you doing on the SERVER and CLIENT (at the domain) level?

I have an iPhone and I can access my work desktop via my VPN and I can also access my home computer via the internet... If you would like we can try and do Remote Assistance... I am just not understanding your terminology and comparing it to your picture (which has a COMPLETELY different computer name btw), I am just not getting it 100%.

I do not mean any disrespect by this, but are you using a translating site or is English a 2nd language?

Edited by Unholee
  Quote
this is why I haven't answered here....it gives me a headache trying to read this and follow it. If someone can put it into some form of legible english I can probably add in my two cents.

Keep your two cents for yourself, I do not bother if you do answer this or not.

  Quote
I am just not understanding your terminology and comparing it to your picture (which has a COMPLETELY different computer name btw), I am just not getting it 100%.

Thanks Unholee

To answer your question, real computer name is P3, for the fourm purpose I have just named it WS-A.

  Quote
I have got this screen locally and via VPN :

User name : support,,,,,,,,,,,,,,,,,,,,,,,,,,member of the domain admin group,,,,,if I write username like this "AML\support" , (Log on to) option will gray out.

Password : forum

Log on to : AML,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,This is my domain name at work,,,,,drop down menu there is another option if I want to login to "This computer"

The screen that I have meant in the quote above is similar to one below :

http://www.bristol.ac.uk/is/computing/advi...ogon-prompt.png

What I want to say if I want to log in I don't need to use this syntax : AML\support, because AML is already chosen in the : " Log on to " option.

  Quote
If you would like we can try and do Remote Assistance...

I appreciate your help and I do not mind to call you if you PM your phone number.

Thanks

  Quote
did you login to the domain or just the local computer because if you logged into the domain it should show the domain in the list

also on the select users screen you can type in the username "domain\username" and it should take it.

The problem was with ' TCP/IP Properties' > DNS section was pointing mistakenly to a default gateway (router) ip address 192.168.0.1 which it should not.

When I changed that to point to the domain controller (server 2003 and DNS as well) ip address 192.168.0.50 it worked like a charm.

Now when if I log in into any workstation (physically in front of a PC or via VPN) as a domain admin I can add a domain user to " Remote Desktop Properties "

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Movavi Video Editor Plus 25.12.0 by Razvan Serea With Movavi Video Editor, you can either enhance your video files with two or three simple steps, or turn them into something completely new. Create your own movies using multiple filters, transitions, and special effects: show multiple videos on one screen with the Picture in picture effect or change the background with the Chroma Key effect, imitate the camera zoom or make your video look like an old-style movie. Adjust video parameters such as brightness, contrast and colors. Stabilize shaky footage, improve video quality and remove defects. Create video presentations, tutorials or educational videos: add titles and record your own narration to create a video with voiceover. Import video from any source: TV-tuner, webcam, camcorder, or VHS. Drop multiple media files onto a timeline and let your imagination do the rest! Features at a glance: Video and audio editing on a timeline Edit, enhance videos Add background music Apply titles and effects Image quality improvement Hollywood-worthy effects High-grade titles and fades Digitize VHS tapes, record video from TV tuners Stabilize any shaky sections Support for a wide range of formats Prepare your videos for uploading to YouTube, Facebook, Vimeo, or any other website New in Movavi Video Editor 2025: Revamped timeline for easier editing The new timeline is now clearer and more streamlined. Get your projects done faster and have more fun with anything – from short vids for socials to longer family movies. Frame-precise cuts in a click Give your videos a sharper look with the new Blade tool. Easily make precise cuts and create eye-catching montages like your favorite bloggers. Pro-quality color correction Get next-level color correction with the same simplicity. Boost colors in a snap and make more viewers fall in love with your videos. AI motion tracking Enhance reality in your videos with additional moving graphics. Just click, and AI will quickly attach any photos, videos, emojis, or memes to objects in your footage. Perfect-match overlay effects Now each overlay effect has 13 blending modes to choose from. Try each of them with the press of a button and pick the one that fits your video perfectly. Best video effects – at your fingertips Create awesome videos in any style with our huge collection of professionally designed effects. Now you can try them all right away, right in the app. Movavi Video Editor 25.12.0 changelog: Just a minor upgrade to keep everything running smoothly. Download: Movavi Video Editor Plus 25.12.0 | 5.1 MB (Shareware) View: Movavi Video Editor Plus Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Major Privacy 0.98.3 Beta by Razvan Serea MajorPrivacy is a cutting-edge privacy and security tool for Windows, offering unparalleled control over process behavior, file access, and network communication. It is a continuation of the PrivateWin10 project. By leveraging advanced kernel-level protections, MajorPrivacy creates a secure environment where user data and system integrity are fully safeguarded. Unlike traditional tools, MajorPrivacy introduces innovative protection methods that ensure mounted encrypted volumes are only accessible by authorized applications, making it the first and only encryption solution of its kind. MajorPrivacy – Ultimate Privacy & Security for Windows key features Process Protection – Isolate processes to block interference from unauthorized apps, even with admin privileges. Software Restriction – Block unwanted apps and DLLs to ensure only trusted software runs. Revolutionary Encrypted Volumes Secure Storage – Create encrypted disk images for sensitive data. Exclusive Access – Unlike traditional tools, only authorized apps can access mounted volumes—blocking all unauthorized processes. File & Folder Protection – Lock down sensitive files and prevent unauthorized access or modifications. Advanced Network Firewall – Control which apps can send or receive data online. DNS Monitoring & Filtering – Track domain access and block unwanted sites (Pi-hole compatible filtering coming soon). Tweak Engine – Disable telemetry, cloud integration, and invasive Windows features for better privacy. Why MajorPrivacy? Kernel-Level Security – Protects at the deepest system level. Unmatched Encryption Protection – Keeps mounted volumes safe from all unauthorized access. Full System Control – Block, isolate, or restrict processes as needed. Enhanced Privacy – Stops Windows & apps from collecting unnecessary data. Perfect for privacy-conscious users, IT pros, and anyone who wants total system control. Major Privacy 0.98.3 Beta changelog: This release of MajorPrivacy introduces several important improvements, bug fixes, and optimizations. The resource access rules engine has been enhanced to include the user as an additional parameter, enabling finer-grained access control. CPU usage has been reduced in both the user interface and background service, improving overall performance. The ImBox feature has been updated to avoid modifying container file timestamps when accessing secure encrypted volumes. Firewall rule handling has been improved for Store Apps on Windows 23H2 and later versions, increasing compatibility and reliability. A critical issue has been resolved in ImBox.exe that affects the mounting of older encrypted volumes; users should use a previous build to recover data and then recreate the volumes using this or a later version. Additionally, several interface and functionality bugs have been addressed: translations now load correctly, the Data Editor’s tree view now functions properly across multiple .dat files, and the Execution Monitor displays entries as expected when a time filter is applied. The “Add to Group” menu now correctly lists all available groups, and folder creation is no longer incorrectly permitted under Directory Listing and Read-only actions. Download: Major Privacy 0.98.3 Beta | 59.4 MB (Open Source) View: MajorPrivacy Home Page | Github Project page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Hi there! Great question and yes, the Twenty Twenty-Four theme (TT4) + Gutenberg does have a few quirks when it comes to spacing and columns. To reduce the spacing between the image and the text in a two-column layout, here are a few things to try:  1. Adjust Block Spacing (Direct Method) Click on the Column Block (the outer wrapper that holds both your image and text). In the right sidebar, under "Block" > "Dimensions", look for the "Block spacing" setting (sometimes called “Gap”). Reduce the value (in px, em, or %) to tighten the space between elements inside that column. 2. Use Padding & Margin Controls Click on the Image block, and then the Text block individually. Under “Dimensions”, adjust the Margin of the Image or Text block (especially bottom or top margin) to reduce extra white space. Try setting margins to 0 or a small number like 8px. 3. Use Group Block (Optional) If the spacing controls aren’t behaving: Wrap the image + text inside a Group block. Then apply padding/margin settings to the inner blocks for better control.
    • Looks interesting, I love the art style. How many people are working on the game?
  • Recent Achievements

    • Reacting Well
      water01 earned a badge
      Reacting Well
    • First Post
      Aidan Helfrich earned a badge
      First Post
    • Collaborator
      bullgod69 earned a badge
      Collaborator
    • Enthusiast
      Ed B went up a rank
      Enthusiast
    • Reacting Well
      Xinotema earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      764
    2. 2
      ATLien_0
      187
    3. 3
      +FloatingFatMan
      151
    4. 4
      Xenon
      118
    5. 5
      wakjak
      113
  • Tell a friend

    Love Neowin? Tell a friend!