You cannot add some local built-in groups when you configure VPN client access in Internet Security and Acceleration Server 2004 (891240)
The information in this article applies to:
- Microsoft Internet Security and Acceleration Server 2004, Standard Edition
SYMPTOMSWhen you configure virtual private network (VPN) client access in Microsoft Internet Security and Acceleration (ISA) Server 2004 to specify which local groups have remote access, you can add only the following groups:
- HelpServicesGroup
- IIS_WPG
- TelnetClients
You cannot add other local built-in groups, such as
Administrators, Backup Operators, or Power Users. CAUSEThis issue occurs because the other local groups are generic. The VPN server cannot distinguish between local administrators and domain administrators.WORKAROUNDTo give remote access to a local administrator, modify the Administrator dial-in properties. To do this, follow these steps:
- On the ISA Server computer, click Start,
point to Administrative Tools, and then click Computer
Management.
- In Computer
Management, click System Tools, click Local
Users and Groups, and then click Users.
- In the Details pane, right-click
Administrators, and then click Properties.
- On the Dial-in tab, click Allow
access under Remote
Access Permission (Dial-in or VPN).
STATUSMicrosoft
has confirmed that this is a problem in the Microsoft products that are listed
in the "Applies to" section.
Modification Type: | Major | Last Reviewed: | 1/25/2005 |
---|
Keywords: | kbtshoot kbprb KB891240 kbAudDeveloper |
---|
|