Skip to content

Commit cfd7fb0

Browse files
author
Simonx Xu
committed
Update system-cannot-determine-license-server-member-tsls.md
1 parent 6ec3ec4 commit cfd7fb0

File tree

1 file changed

+7
-6
lines changed

1 file changed

+7
-6
lines changed

support/windows-server/remote/system-cannot-determine-license-server-member-tsls.md

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -44,36 +44,37 @@ Review the members of the **Terminal Server License Servers** group by using the
4444

4545
If you have confirmed that the connectivity is well established with a domain controller in your network, and the issue still persists, you might have security restrictions enforced on your domain controller. These restrictions control which users can enumerate users and groups in Active Directory (AD).
4646

47-
In this case, you're encountering security restrictions that were introduced in Windows Server 2016 and subsequently added to all other Windows operating systems through an update. These restrictions limit the client's ability to make remote SAM calls to the local SAM database and Active Directory.
47+
In this case, you're encountering security restrictions that were introduced in Windows Server 2016 and later added to all other Windows operating systems through an update. These restrictions limit the client's ability to make remote SAM calls to the local SAM database and Active Directory.
4848

49-
For more information about this security settings, see the [Network access: Restrict clients allowed to make remote calls to SAM](/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls) security policy setting.
49+
For more information about this security setting, see the [Network access: Restrict clients allowed to make remote calls to SAM](/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls) security policy setting.
5050

5151
This policy, when enabled, affects the license server verification of its membership in the TSLS domain group, if the license server isn't part of the allowed users to make remote calls to AD.
5252

5353
By default, the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting isn't defined. If you define it, you can edit the default Security Descriptor Definition Language (SDDL) string to explicitly allow or deny users and groups to make remote calls to SAM.
5454

5555
If the policy setting is left blank after being defined, the policy isn't enforced.
5656

57-
To verify if you're encountering these restrictions, check one of the following:
57+
To verify if you're encountering these restrictions, check one of the following points:
5858

5959
- On the logon domain controller (DC) for the Remote Desktop License Server, check if the following registry key is present:
6060

6161
`HKLM\System\CurrentControlSet\Control\Lsa\RestrictRemoteSAM`
6262

63-
If this key is present, this means the DC is configured with the SAM restrictions policy.
63+
If this key is present, which means the DC is configured with the SAM restrictions policy.
64+
6465
- Check if the following Group Policy Object is present and applied on the DC:
6566

6667
**Computer Configuration** > **Windows Settings** > **Security Settings** > **Local Policies** > **Security Options** > **Network access: Restrict clients allowed to make remote calls to SAM**
6768

6869
> [!NOTE]
69-
> This behavior is expected when restricting SAM calls to the DC. However, it has no impact on the RDS Licensing functionality in terms of issuing client access licenses (CALs) and maintaining connectivity with its peers in the RDS farm.
70+
> This behavior is expected when restricting SAM calls to the DC. However, it has no effect on the RDS Licensing functionality in terms of issuing client access licenses (CALs) and maintaining connectivity with its peers in the RDS farm.
7071
7172
To verify if the Remote Desktop license server is affected by this policy, see [related events](/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls#related-events) on the domain controller.
7273

7374
To allow the Remote Desktop license server to make remote SAM calls to Active Directory, use Group Policy to add the Remote Desktop license server computer account to the list of allowed accounts under this policy: **Network access: Restrict clients allowed to make remote calls to SAM**.
7475

7576
> [!NOTE]
76-
> Restarts aren't required to enable, disable or modify the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting, including audit only mode. Changes become effective without a device restart when they're saved locally or distributed through Group Policy.
77+
> Restarts aren't required to enable, disable, or modify the **Network access: Restrict clients allowed to make remote calls to SAM** security policy setting, including audit only mode. Changes become effective without a device restart when they're saved locally or distributed through Group Policy.
7778
7879
## Contact Microsoft Support
7980

0 commit comments

Comments
 (0)