terminal服务器2008年login:访问拒绝RDP尝试

当我尝试将RDP装入Server 2008terminal服务器时,出现“拒绝访问”和“确定”button的消息。 我正确设置了授权模式(每个用户),并且已经设置为允许所有的远程连接。 我在安全事件日志中得到以下内容:

Log Name: Security Source: Microsoft-Windows-Security-Auditing Date: 28/06/2012 12:01:16 Event ID: 4656 Task Category: File System Level: Information Keywords: Audit Failure User: N/A Computer: FQDN COMPUTER Description: A handle to an object was requested. Subject: Security ID: DOMAIN\ACCOUNT Account Name: ACCOUNT Account Domain: DOMAIN Logon ID: 0xbbe3f Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ServerManager.msc Handle ID: 0x0 Process Information: Process ID: 0x60c Process Name: C:\Windows\System32\mmc.exe Access Request Information: Transaction ID: {00000000-0000-0000-0000-000000000000} Accesses: READ_CONTROL SYNCHRONIZE WriteData (or AddFile) AppendData (or AddSubdirectory or CreatePipeInstance) WriteEA ReadAttributes WriteAttributes Access Reasons: READ_CONTROL: Granted by D:(A;;0x1200a9;;;BA) SYNCHRONIZE: Granted by D:(A;;0x1200a9;;;BA) WriteData (or AddFile): Not granted AppendData (or AddSubdirectory or CreatePipeInstance): Not granted WriteEA: Not granted ReadAttributes: Granted by ACE on parent folder D:(A;;0x1301bf;;;BA) WriteAttributes: Not granted Access Mask: 0x120196 Privileges Used for Access Check: - Restricted SID Count: 0 Event Xml: <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"> <System> <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" /> <EventID>4656</EventID> <Version>1</Version> <Level>0</Level> <Task>12800</Task> <Opcode>0</Opcode> <Keywords>0x8010000000000000</Keywords> <TimeCreated SystemTime="2012-06-28T15:01:16.975080700Z" /> <EventRecordID>1535565</EventRecordID> <Correlation /> <Execution ProcessID="540" ThreadID="556" /> <Channel>Security</Channel> <Computer>FQDN COMPUTER/Computer> <Security /> </System> <EventData> <Data Name="SubjectUserSid">S-1-5-21-205301047-3902605089-2438454170-21511219</Data> <Data Name="SubjectUserName">ACCOUNT</Data> <Data Name="SubjectDomainName">DOMAIN</Data> <Data Name="SubjectLogonId">0xbbe3f</Data> <Data Name="ObjectServer">Security</Data> <Data Name="ObjectType">File</Data> <Data Name="ObjectName">C:\Windows\System32\ServerManager.msc</Data> <Data Name="HandleId">0x0</Data> <Data Name="TransactionId">{00000000-0000-0000-0000-000000000000}</Data> <Data Name="AccessList">%%1538 %%1541 %%4417 %%4418 %%4420 %%4423 %%4424 </Data> <Data Name="AccessReason">%%1538: %%1801 D:(A;;0x1200a9;;;BA) %%1541: %%1801 D:(A;;0x1200a9;;;BA) %%4417: %%1805 %%4418: %%1805 %%4420: %%1805 %%4423: %%1811 D:(A;;0x1301bf;;;BA) %%4424: %%1805 </Data> <Data Name="AccessMask">0x120196</Data> <Data Name="PrivilegeList">-</Data> <Data Name="RestrictedSidCount">0</Data> <Data Name="ProcessId">0x60c</Data> <Data Name="ProcessName">C:\Windows\System32\mmc.exe</Data> </EventData> </Event> 

有任何想法吗?

看起来它试图在第一次login时打开服务器pipe理器,但是用户没有权限这么做。

用户是否login到服务器上的本地pipe理员?

在服务器pipe理器中,在第一个屏幕上单击“不要在login时显示此控制台”。

这是解决scheme:

http://blog.danielcosta.pt/?p=371

远程桌面服务正在使用“LocalSystem”帐户运行。 如果您将此registry项与其他工作的服务器进行比较,您可以看到,您需要保留此服务器与“NT AuthorityNetworkService”运行。