Skip to content

Commit 9a9fcdc

Browse files
authored
Edit review
1 parent 4f8a9b5 commit 9a9fcdc

File tree

1 file changed

+20
-20
lines changed

1 file changed

+20
-20
lines changed

support/windows-server/remote/system-cannot-determine-license-server-member-tsls.md

Lines changed: 20 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -1,80 +1,80 @@
11
---
2-
title: The system cannot determine if the license server is member of TSLS Group on AD DS
2+
title: System Cannot Determine If the License Server Is Member of TSLS Group on AD DS
33
description: Troubleshoot an error when you review the configuration of a Remote Desktop Services (RDS) license server.
4-
ms.date: 02/10/2025
4+
ms.date: 02/13/2025
55
manager: dcscontentpm
66
audience: itpro
77
ms.topic: troubleshooting
88
ms.reviewer: kaushika, v-lianna
99
ms.custom: sap:Remote Desktop Services and Terminal Services\Licensing for Remote Desktop Services (Terminal Services), csstroubleshoot
1010
---
11-
# The system cannot determine if the license server is member of TSLS Group on Active Directory Domain Services (AD DS) because the AD DS cannot be contacted
11+
# The system cannot determine if the license server is member of TSLS Group on Active Directory Domain Services (AD DS)
1212

13-
This article helps troubleshoot an error when you review the configuration of a Remote Desktop Services (RDS) license server.
13+
This article helps troubleshoot an error that occurs when you review the configuration of a Remote Desktop Services (RDS) license server.
1414

15-
You have a domain-joined server running the Remote Desktop license server role. When you review the configuration status from the Remote Desktop Licensing Manager console, you receive the following error message on the configuration window:
15+
You have a domain-joined server running the Remote Desktop license server role. When you review the configuration status from the Remote Desktop Licensing Manager console, you receive the following error message in the configuration window:
1616

1717
> The system cannot determine if the license server is member of TSLS Group on Active Directory Domain Services (AD DS) because the AD DS cannot be contacted.
1818
1919
Here are some possible causes:
2020

21-
- The Remote Desktop license server can't contact any domain controller in the network.
21+
- The Remote Desktop license server can't contact any domain controller (DC) in the network.
2222
- The Remote Desktop license server isn't a member of the Terminal Server License Servers (TSLS) domain group.
23-
- Security restrictions are enforced on domain controllers to restrict remote calls to Security Account Manager (SAM).
23+
- Security restrictions are enforced on DCs to restrict remote calls to the Security Account Manager (SAM).
2424

2525
Follow these steps to troubleshoot the error while verifying if the Remote Desktop license server is part of the TSLS domain group.
2626

2727
## Step 1: Verify domain connectivity
2828

29-
If the server is part of the TSLS domain group, verify that the license server can reach a valid domain controller in your domain.
29+
If the server is part of the TSLS domain group, verify that the license server can reach a valid DC in your domain.
3030

31-
When domain connectivity is lost, you might notice other symptoms such as Group Policy update failures, logon failures, or a loss of trust relationship with the domain controller.
31+
When domain connectivity is lost, you might notice other symptoms, such as Group Policy update failures, logon failures, or a loss of trust relationship with the DC.
3232

3333
If you notice these symptoms, work with your system administrator to resolve the connectivity issue.
3434

3535
## Step 2: Check group membership
3636

3737
Review the members of the **Terminal Server License Servers** group by using the following steps:
3838

39-
1. On a domain controller, open the **Active Directory Users and Computers** console.
39+
1. On a DC, open the **Active Directory Users and Computers** console.
4040
2. Select the **Builtin** container, and then open the **Terminal Server License Servers** group in the right pane.
4141
3. Select **Members**, and then verify that the license server computer object is listed.
4242

4343
## Step 3: Review security restrictions
4444

45-
If you have confirmed that the connectivity is well established with a domain controller in your network, and the issue still persists, you might have security restrictions enforced on your domain controller. These restrictions control which users can enumerate users and groups in Active Directory (AD).
45+
If you have confirmed that the connectivity is well established with a DC in your network and the issue persists, you might have security restrictions enforced on your DC. These restrictions control which users can enumerate users and groups in Active Directory (AD).
4646

47-
In this case, you're encountering security restrictions that were introduced in Windows Server 2016 and later added to all other Windows operating systems through an update. These restrictions limit the client's ability to make remote SAM calls to the local SAM database and Active Directory.
47+
In this case, you're encountering security restrictions that were introduced in Windows Server 2016 and later added to all other Windows operating systems through an update. These restrictions limit the client's ability to make remote SAM calls to the local SAM database and AD.
4848

4949
For more information about this security setting, see the [Network access: Restrict clients allowed to make remote calls to SAM](/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls) security policy setting.
5050

51-
This policy, when enabled, affects the license server verification of its membership in the TSLS domain group, if the license server isn't part of the allowed users to make remote calls to AD.
51+
This policy, when enabled, affects the verification of the license server's membership in the TSLS domain group if the license server isn't among the users allowed to make remote calls to AD.
5252

5353
By default, the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting isn't defined. If you define it, you can edit the default Security Descriptor Definition Language (SDDL) string to explicitly allow or deny users and groups to make remote calls to SAM.
5454

5555
If the policy setting is left blank after being defined, the policy isn't enforced.
5656

5757
To verify if you're encountering these restrictions, check one of the following points:
5858

59-
- On the logon domain controller (DC) for the Remote Desktop License Server, check if the following registry key is present:
59+
- On the logon DC for the Remote Desktop license server, check if the following registry key is present:
6060

6161
`HKLM\System\CurrentControlSet\Control\Lsa\RestrictRemoteSAM`
6262

63-
If this key is present, which means the DC is configured with the SAM restrictions policy.
63+
If this key is present, it means the DC is configured with the SAM restriction policy.
6464

65-
- Check if the following Group Policy Object is present and applied on the DC:
65+
- Check if the following Group Policy Object is present and applied to the DC:
6666

6767
**Computer Configuration** > **Windows Settings** > **Security Settings** > **Local Policies** > **Security Options** > **Network access: Restrict clients allowed to make remote calls to SAM**
6868

6969
> [!NOTE]
70-
> This behavior is expected when restricting SAM calls to the DC. However, it has no effect on the RDS Licensing functionality in terms of issuing client access licenses (CALs) and maintaining connectivity with its peers in the RDS farm.
70+
> This behavior is expected when SAM calls are restricted to the DC. However, it doesn't affect the RDS Licensing functionality in terms of issuing client access licenses (CALs) and maintaining connectivity with its peers in the RDS farm.
7171
72-
To verify if the Remote Desktop license server is affected by this policy, see [related events](/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls#related-events) on the domain controller.
72+
To verify if the Remote Desktop license server is affected by this policy, see the [related events](/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls#related-events) on the DC.
7373

74-
To allow the Remote Desktop license server to make remote SAM calls to Active Directory, use Group Policy to add the Remote Desktop license server computer account to the list of allowed accounts under this policy: **Network access: Restrict clients allowed to make remote calls to SAM**.
74+
To allow the Remote Desktop license server to make remote SAM calls to AD, use Group Policy to add the Remote Desktop license server computer account to the list of allowed accounts under this policy: **Network access: Restrict clients allowed to make remote calls to SAM**.
7575

7676
> [!NOTE]
77-
> Restarts aren't required to enable, disable, or modify the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting, including audit only mode. Changes become effective without a device restart when they're saved locally or distributed through Group Policy.
77+
> Restarts aren't required to enable, disable, or modify the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting, including audit-only mode. Changes become effective without a device restart when they're saved locally or distributed through Group Policy.
7878
7979
## Contact Microsoft Support
8080

0 commit comments

Comments
 (0)