The problem
Opening RDP sessions to servers from accounts with logon-to restrictions no longer work. When they try they get a message from the RDP client:
"The system administrator has limited the computers you can log on with. Try logging on at a different computer. If the problem continues, contact your system administrator or technical support."
Background
The servers are accessed by an external consultant who vpns in and opens an RDP session to the servers. The consultants account is a member of the admistrators group on the boxes in question.
In the domain account used by the consultant I added a restriction under user account > Account tab > logon to button. Here I added the server nodenames.
This has been working fine for a couple of years. The consultant only connects every few months so this could have been broken for some time.
What I've tried
- Removing and re-adding the servers to the list.
- Adding the accounts to the local security policy > local policy > assigned user rights > permit login via RDP (I'm translating those texts as server is not english language)
None of those changes had any effect.
Workaround
To allow them to log via RDP in I've had to remove the logon-to restriction on their account object. If I change the account to permit logging onto any machine, the problem disappears.
Other info
- The servers are all running Windows 2019
- All are fully patched up until a few weeks ago.
- The user account can login via the console with the restriction in place.
- I have to add the user account to the local admin group of any machines they are accessing and so they can't access any others but I'd prefer to have the extra restriction active.
Is anyone aware of a breaking change in one of the recent CU packs which affects this functionality?
The system administrator has limited the computers you can log on with
that is an attribute of the account.`Here I added the server nodenames.
how many and what is the total length of the attribute? The attribute has a relatively short length. None of the other things you are doing will affect this.