Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How to give permissions with MetaFrame 1

Status
Not open for further replies.

joepc

MIS
Jul 26, 2002
647
US
I'm having a problem with permissions with Ctrix MetaFrame for 2000 servers 1.8. We just installed Active Directory on our citrix server and ever since we did that only a user with admin privs can login.

Does anyone know where I can go to change the permissions for metaframe. I went to the application manager and gave permissions to Domain Users and that doesn't work. Am I not in the right place? I'm not familar with Citrix so if any one could help me that would be great.

Thanks!
 
Are your clients receiving an error message when they try to logon your Metaframe server such as "You do not have access to logon to this session"? If so, you may need to check your permissions for the ICA connection on your Metaframe Server. Also, you may want to check to see if your clients can connect and logon via RDP instead of ICA to rule out a protocol problem.
 
It looks like they are logging in via rdp. It just tells me that I do not have the correct user credetials. I am using a valid user. I can logon with anyone who has admin privs.
 
Check the permissions for ICA
Open Citrix Connection Configuration
Right click ica-tcp - select permissions
Is Domain Users listed and have access to login?
 
Domain users is listed and given access.
 
Check the local security GPO on the MF... and see who has permissions to log in...

Hope this helps-
Brandon
 
So far I have checked permissions in the citrix connection configuration. ICA-tcp & rdp-tcp2 are set allow everyone, domain users, and admins. Is there anywhere else I should have to edit any permissions?

I created a new user and gave him admin privs. He can logon with no problem. Take them away and just make him a domain user I get an error stating the credentials I supplied are incorrect.

There is something somewhere that is not allowing to logon.
 
Run Box: MMC
Console Menu: Add/Remove Snap In
Click ADD
Choose GROUP POLICY
Leave default (Local Computer)
Click Finish,
Click Close,
Click OK,
now drill down to this:
-Local computer policy\Computer Config\Windows Settings\Security Settings\Local Policies\User Rights AssignmentMake sure that your Domain Users are added to the LOG ON LOCALLY section...

I think this is your problem...
Brandon
 
Brandon,

Thanks that didn't quite do it but it did sort of answer my question. I added domain users but it didn't say that it was effictive. I tried logging in and got the error. However I did notice that backup operators did say policy was effictive and I made the user part of it and I was able to login.

You da man.
 
Thanks Joe- Glad to help... You may want to investigate why it was not effective for your Domain Users... I would suggest it's a Domain Policy that is taking precedence in a GPO...

Email me at Bwitcher@apexsystemsinc.com

Later-
Brandon
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top