This message was deleted.
# _general
s
This message was deleted.
k
How about adding the same group to the Remote Desktop users group? It should produce the same result
j
The GPO for "allow logon" and actually adding the groups to the RDP Users group need to be configured separately, don't they?
k
They do, but I don't think you need to configure "allow logon" if the user is a member of the Rmote Desktop users group
j
Oh, I thought you did - unless of course the "Remote Desktop Users" is allowed that user right by default. Maybe my usual environments are higher security
c
@Kasper Johansen Domain users group is already added to local RDP group.
k
Unless you configre something "non default" on the allow logon through remote desktop services setting, nothing else should be configured to allow RDP access
c
We're adding remote desktop users group to that allow logon through remote desktop services policy so that all users who are part of that local RDP group are allowed through Citrix.
By default only admins are allowed on that RDP group.
local RDP group I mean.
k
Yes, but you can add users or groups to that group using GPO
c
@James Rankin My bad, Thats what we did.. updated above message.
👍 1
j
So can't you just use Restricted Groups GPO or Local Users and Groups GPP to fill the local RDP Users group with the users you need?
And then only "Admins" and "RDP Users" local groups need to have the security right defined?
c
Domain users AD group is added to local Remote desktop users group (this is OK). Local Remote desktop group is added to "allow logon through remote desktop services" policy. This is added through a GPO. It is failing for some reason.
j
Are you doing it via domain GPO or local GP?
But I'm still a bit confused as to why you need to change it because I'm sure Remote Desktop Users gets that user right by default......
c
We are doing it with a domain GPO.
can you run rsop in that same machine?
j
OK, then does gpresult /r show the domain GPO being applied?
c
I wonder if that RDP group is added through a domain or local GPO
j
If it does, then are there any errors in the event logs during the application of the GPO?
c
For now, I am only working on verifying on whether we have that remote desktop users group in allow logon through remote desktop services policy in secpol. Why that GPO is not being applied - i m going to involve our windows team for that.
m
If you want users to be able to RDP you need to add them to the Direct Access group too. https://support.citrix.com/article/CTX477298/1912cu6-how-to-enable-users-rdp-after-vda-installation
💯 4
c
As Mike says
j
Yep, Direct Access group is always the one people forget