<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logon Failure. The user has not been granted the requested logon type at this computer in Managing Users</title>
    <link>https://community.cisco.com/t5/managing-users/logon-failure-the-user-has-not-been-granted-the-requested-logon/m-p/4881518#M726</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;We operate a Windows RDS environment and have protection at the rdweb layer and then protection on published applications using the duo-rdp client.&lt;BR /&gt;
We installed the duo-win-login.exe on a session host to protect the published application and added one user to test via ad-sync, however since installing the exe using the following powershell command (using elevated PS),&lt;BR /&gt;
(C:\Windows\Temp\Duo\duo-win-login-4.1.3.exe /S /V" /qn IKEY=“DXXXXX” SKEY=“XXXXXXXXXXXXX” HOST=“&lt;A href="http://api-xxxxxxx.duosecurity.com" rel="noopener nofollow ugc"&gt;■■■■■■■■■■■■■■■■■■■■■■■■■■■&lt;/A&gt;” LOGFILE_MAXSIZEMB="&lt;SPAN class="hashtag"&gt;#100&lt;/SPAN&gt;" AUTOPUSH="&lt;SPAN class="hashtag"&gt;#1&lt;/SPAN&gt;" FAILOPEN="&lt;SPAN class="hashtag"&gt;#1&lt;/SPAN&gt;" SMARTCARD="&lt;SPAN class="hashtag"&gt;#0&lt;/SPAN&gt;" RDPONLY="&lt;SPAN class="hashtag"&gt;#0&lt;/SPAN&gt;"")&lt;BR /&gt;
ALL users whether they were in the Duo console or not now receive the error “Logon Failure. The user has not been granted the requested logon type at this computer” when trying to open the RDP published application from rdweb.&lt;/P&gt;
&lt;P&gt;This error is normally seen if the user is not part of the ‘Remote Desktop Users’ local group on that server but the RDS session collection automatically adds this and they are still in there.&lt;BR /&gt;
This all worked before installing the duo exe.&lt;/P&gt;
&lt;P&gt;I have to add ALL users as local admins on the server for them to launch the published app since installing Duo RDP, obviously i don’t want to do this so trying to understand why this happens.&lt;/P&gt;
&lt;P&gt;Anyone seen this?&lt;BR /&gt;
Is it because the exe was ran elevated with admin?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;
Steve&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 02 Jul 2021 07:59:00 GMT</pubDate>
    <dc:creator>s_hughes78</dc:creator>
    <dc:date>2021-07-02T07:59:00Z</dc:date>
    <item>
      <title>Logon Failure. The user has not been granted the requested logon type at this computer</title>
      <link>https://community.cisco.com/t5/managing-users/logon-failure-the-user-has-not-been-granted-the-requested-logon/m-p/4881518#M726</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;We operate a Windows RDS environment and have protection at the rdweb layer and then protection on published applications using the duo-rdp client.&lt;BR /&gt;
We installed the duo-win-login.exe on a session host to protect the published application and added one user to test via ad-sync, however since installing the exe using the following powershell command (using elevated PS),&lt;BR /&gt;
(C:\Windows\Temp\Duo\duo-win-login-4.1.3.exe /S /V" /qn IKEY=“DXXXXX” SKEY=“XXXXXXXXXXXXX” HOST=“&lt;A href="http://api-xxxxxxx.duosecurity.com" rel="noopener nofollow ugc"&gt;■■■■■■■■■■■■■■■■■■■■■■■■■■■&lt;/A&gt;” LOGFILE_MAXSIZEMB="&lt;SPAN class="hashtag"&gt;#100&lt;/SPAN&gt;" AUTOPUSH="&lt;SPAN class="hashtag"&gt;#1&lt;/SPAN&gt;" FAILOPEN="&lt;SPAN class="hashtag"&gt;#1&lt;/SPAN&gt;" SMARTCARD="&lt;SPAN class="hashtag"&gt;#0&lt;/SPAN&gt;" RDPONLY="&lt;SPAN class="hashtag"&gt;#0&lt;/SPAN&gt;"")&lt;BR /&gt;
ALL users whether they were in the Duo console or not now receive the error “Logon Failure. The user has not been granted the requested logon type at this computer” when trying to open the RDP published application from rdweb.&lt;/P&gt;
&lt;P&gt;This error is normally seen if the user is not part of the ‘Remote Desktop Users’ local group on that server but the RDS session collection automatically adds this and they are still in there.&lt;BR /&gt;
This all worked before installing the duo exe.&lt;/P&gt;
&lt;P&gt;I have to add ALL users as local admins on the server for them to launch the published app since installing Duo RDP, obviously i don’t want to do this so trying to understand why this happens.&lt;/P&gt;
&lt;P&gt;Anyone seen this?&lt;BR /&gt;
Is it because the exe was ran elevated with admin?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;
Steve&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 02 Jul 2021 07:59:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/logon-failure-the-user-has-not-been-granted-the-requested-logon/m-p/4881518#M726</guid>
      <dc:creator>s_hughes78</dc:creator>
      <dc:date>2021-07-02T07:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: Logon Failure. The user has not been granted the requested logon type at this computer</title>
      <link>https://community.cisco.com/t5/managing-users/logon-failure-the-user-has-not-been-granted-the-requested-logon/m-p/4881519#M727</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Managed to find the below thread which in turn gave the duo guide.&lt;BR /&gt;
Pre-req missed around GPO’s for local logon, i’ll take a look at this.&lt;/P&gt;
&lt;ASIDE class="quote quote-modified" data-post="3" data-topic="2220"&gt;
  &lt;DIV class="title"&gt;
    &lt;DIV class="quote-controls"&gt;&lt;/DIV&gt;
    &lt;IMG width="20" height="20" src="https://community.cisco.com/legacyfs/online/ciscoduo/letters/j_c77e96.png" style="display : inline;" /&gt;
    &lt;A href="https://community.duo.com/t/duo-for-rdp-windows-prerequisites/2220/3"&gt;Duo for RDP/Windows prerequisites&lt;/A&gt; &lt;A class="badge-wrapper  bullet" href="https://community.cisco.com/c/protecting-applications-forum/microsoft/41"&gt;&lt;SPAN class="badge-category-parent-bg" style="background-color: #F7941D;"&gt;&lt;/SPAN&gt;&lt;SPAN class="badge-category-bg" style="background-color: #F7941D;"&gt;&lt;/SPAN&gt;&lt;SPAN style="" data-drop-close="true" class="badge-category clear-badge"&gt;Microsoft&lt;/SPAN&gt;&lt;/A&gt;
  &lt;/DIV&gt;
  &lt;BLOCKQUOTE&gt;
    When I installed DUO RDP Windows logon to a RDS session host used to provide remote apps for internal users, the users RDP access breaks.  They get “Logon failure the user has not been granted the requested logon type” .  If I give the remote app user group the “logon on locally” right they can get in again.  The problem is they should not have this right, since they are only allowed RDP access to particular applications.  They functioned fine without it prior to implementing DUO.  I tried to ad…
  &lt;/BLOCKQUOTE&gt;
&lt;/ASIDE&gt;

&lt;P&gt;&lt;A href="https://help.duo.com/s/article/1093?language=en_US" class="onebox" target="_blank" rel="noopener nofollow ugc"&gt;https://help.duo.com/s/article/1093?language=en_US&lt;/A&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 02 Jul 2021 09:52:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/logon-failure-the-user-has-not-been-granted-the-requested-logon/m-p/4881519#M727</guid>
      <dc:creator>s_hughes78</dc:creator>
      <dc:date>2021-07-02T09:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: Logon Failure. The user has not been granted the requested logon type at this computer</title>
      <link>https://community.cisco.com/t5/managing-users/logon-failure-the-user-has-not-been-granted-the-requested-logon/m-p/4881520#M728</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Creating a GPO for the two additional user rights as per the Duo support link and applying to server OU fixed this.&lt;BR /&gt;
Just for anyone else reading in the future.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 02 Jul 2021 13:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/logon-failure-the-user-has-not-been-granted-the-requested-logon/m-p/4881520#M728</guid>
      <dc:creator>s_hughes78</dc:creator>
      <dc:date>2021-07-02T13:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Logon Failure. The user has not been granted the requested logon type at this computer</title>
      <link>https://community.cisco.com/t5/managing-users/logon-failure-the-user-has-not-been-granted-the-requested-logon/m-p/4881521#M729</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Thanks for sharing &lt;A class="mention" href="https://community.duo.com/u/s_hughes78"&gt;@s_hughes78&lt;/A&gt;! Glad you were able to resolve this using the info you found in a past thread and the Duo guide. &lt;IMG width="20" height="20" src="https://community.cisco.com/legacyfs/online/ciscoduo/cdn_emojis/twitter/+1.png" style="display : inline;" /&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 02 Jul 2021 14:03:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/logon-failure-the-user-has-not-been-granted-the-requested-logon/m-p/4881521#M729</guid>
      <dc:creator>Amy2</dc:creator>
      <dc:date>2021-07-02T14:03:25Z</dc:date>
    </item>
  </channel>
</rss>

