Cause
This error is typically caused by misconfigured the User Rights Assignment policy. The main reasons include:
Policy denial: The Deny log on through Remote Desktop Services policy explicitly blocks the target user.
Insufficient permissions: The target user is not in an authorized remote logon group, such as
Remote Desktop UsersorAdministrators.
Solution
Before modifying any permission settings, we recommend creating a snapshot to back up your data. This prevents data loss and system lockout in case of a configuration error. Creating a snapshot incurs charges. For more information, see Snapshot Billing.
Step 1: Check the deny policy
A deny policy takes precedence over an allow policy. First, check if the user is explicitly denied remote logon rights.
Log on to an ECS instance using a VNC connection.
Go to ECS console - Instance. In the top navigation bar, select the target region and resource group.
Go to the details page of the target instance. Click Connect and select VNC. Enter the username and password to log on to the ECS instance.
Search for and open Local Security Policy.
In the left navigation pane, expand .
In the list on the right, find and double-click Deny log on through Remote Desktop Services.
Check if the target user is in the list. If so, select the user, click Remove, then click OK.
Step 2: Check the allow policy
Ensure the specified user groups have the correct remote logon rights.
Search for and open Local Security Policy.
In the left navigation pane, expand .
Double-click the Allow log on through Remote Desktop Services policy.
Confirm that the list contains the following user groups. If a group is missing, click Add User or Group, enter the group name, then click OK.
AdministratorsRemote Desktop Users
Step 3: Check user group membership
Verify that the target user belongs to an authorized group. This allows the user to inherit remote logon permissions.
Search for
lusrmgr.mscand open Local Users and Groups (Local).In the left navigation pane, click Users.
In the user list on the right, find and double-click the user who cannot log on.
In the user properties dialog box, click the Member Of tab.
Confirm that the user is a member of the
Remote Desktop UsersorAdministratorsgroup. If not, click Add to add the user to theRemote Desktop Usersgroup.Users in the
Administratorsgroup have full control over the system. To enhance security, add non-administrative users to theRemote Desktop Usersgroup instead of theAdministratorsgroup.
Step 4: Verify the configuration
Open a Remote Desktop client and connect to the Windows instance using the target user's credentials. Verify that the issue is resolved.