已加入域的Windows Server 2016 VM:Virtual Machine Administrator Login角色无法RDP
Ah, I’ve run into this exact scenario before—let’s break down the root cause first, then walk through the fixes.
核心原因:Azure RBAC ≠ 本地VM登录权限
The Virtual Machine Administrator Login role is an Azure-level RBAC permission, not a local VM security setting. All it does is grant users the ability to:
- Retrieve VM local admin credentials via the Azure Portal/CLI
- Generate RDP files to connect to the VM (via Azure Bastion, VPN, etc.)
- Run certain VM management commands through Azure tools
It does not automatically add users to the VM’s local Remote Desktop Users group or grant them the "Allow log on through Remote Desktop Services" local user right—which is why you can only connect when you manually add the user to that list.
解决方案:配置本地VM权限(批量推荐组策略)
Since your VM is domain-joined, the cleanest, most scalable fix is using Group Policy (GPO). If you only have one VM, you can also configure local security settings directly.
方法1:域组策略(推荐用于多VM)
- On your domain controller, open the Group Policy Management Console (GPMC).
- Create a new GPO (or edit an existing one) targeted at your Windows Server 2016 VMs.
- Navigate to:
Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > User Rights Assignment - Edit the Allow log on through Remote Desktop Services policy:
- Add the domain user(s) or domain group(s) that have the
Virtual Machine Administrator LoginAzure RBAC role.
- Add the domain user(s) or domain group(s) that have the
- Optional but recommended: Also edit the Allow log on locally policy and add the same users/groups—this ensures full local login permissions (RDP relies on this under the hood).
- Force group policy update on your VM(s) by running this command in an elevated PowerShell prompt:
gpupdate /force
方法2:本地VM安全配置(单VM场景)
- Log into the VM via the local admin account (or your manually added user).
- Open Local Security Policy (
secpol.msc) from the Start menu. - Navigate to:
Local Policies > User Rights Assignment - Edit Allow log on through Remote Desktop Services and add your domain user/group.
- Alternatively, open Computer Management, go to
Local Users and Groups > Groups > Remote Desktop Users, and add the user/group directly.
验证配置生效
To confirm the settings applied without logging into the VM directly, use Azure CLI to run a PowerShell command on the VM:
az vm run-command invoke --command-id RunPowerShellScript --name <your-vm-name> --resource-group <your-rg-name> --scripts "net localgroup 'Remote Desktop Users'"
This will return the members of the Remote Desktop Users group on the VM—you should see your domain user/group listed.
额外注意点(无公网IP场景)
Since your VM doesn’t have a public IP, I assume you’re using Azure Bastion or a VPN/ExpressRoute to connect. Make sure:
- Bastion is configured to allow domain authentication (it’s enabled by default, but double-check if you’ve modified settings).
- Your network connection (VPN/Bastion) has access to the VM’s private IP and RDP port (3389).
内容的提问来源于stack exchange,提问作者Azi M

