2012 R2 RemoteApp User Assignment RRS feed

  • Question

  • I have a small test lab. One DC, one RDSH server, and one RDCB/RDWA server.

    There seems to be an issue with the user assignment properties of remoteapps. Scenario:

    I publish a collection and set the group to "domain users."  I publish two remoteapps to the collection. I then edit the properties of App1, expand the "user assignment" pane. I select the radio button to make the remoteapp only available to certain users. I add "user1."  I repeat the same for app2, but add only "user2."  User1 and User2 are both members of "domain users."

    The test under user assignment seems to state that RDWA will only display icons for the apps the user has been assigned. However this is not the actual behavior. If User1 logs into RDWA, both apps are present (app2 should not be.)  Similarly, user2 sees both apps (app1 should not be present.)  Both users can launch both apps as well.

    So I see one of three possibilities:

    1) There is a bug.

    2) This particular feature has been deprecated and the intended way to segment apps is now by collection, or

    3) I am missing something insanely simple and will feel quite silly when someone points it out to me.

    Fire away...


    Friday, November 14, 2014 1:48 AM


All replies

  • Hi Cliff,

    Thank you for posting in Windows Server Forum.

    The user who logins to access RemoteApp must sign with “Domain\username” and not only username. Also the computer that is actually performing the check of the user’s credentials against the RemoteApp program’s ACL must be either a member of the domain’s Windows Authorization Access Group, or must be joined to domain. We can also assign the RemoteApp to users with PowerShell command.

    Please check certain specification and requirement with following article.
    Introducing RemoteApp User Assignment

    Hope it helps!


    Dharmesh Solanki

    TechNet Community Support

    Monday, November 17, 2014 2:46 AM
  • Hi,

    Thanks for posting in Windows Server Forum.

    As this thread has been quiet for a while, we assume that the issue has been resolved. At this time, we will mark it as ‘Answered’ as the previous steps should be helpful for many similar scenarios.
    If the issue still persists, please feel free to  reply this post directly so we will be notified to follow it up. 

    BTW,  we’d love to hear your feedback about the solution. By sharing your experience you can help other community members facing similar problems. 

    Thanks for your Support & understanding.


    Dharmesh Solanki

    TechNet Community Support

    Wednesday, November 26, 2014 3:13 AM
  • Hi Dharmesh,

    I am facing the same problem as Cliff. Done all troubleshoot. The link which you shared above is not working any more. Can you please re-share something else. 

    My scenario: (All servers 2012R2)

    1 RDWeb + Gateway Server

    1 RDweb + License Server

    1 Session hosts (server is running three app)

    There is a AD Group called "RDS Server access" which is member of "Remote Desktop User" on each of this Session host server (Local Group: Remote Desktop User). " RDS Server access" group is also added in Session collection of each server.

    We have RDS Host grp 1, 2 and 3 which have users who can access remote app 1, 2 and 3 on server respectiviely.

    Users who will access server app 1 are in RDS Host Grp 1, Users for server app 2 in grp 2 and so on.

    RDS Host Grp 1, 2, 3 are in "user assignment" (properties of remoteapp program).

    STILL ALL USERS ARE ABLE TO SEE ALL APPs rather then restricting them.

    Any help is appreciated.



    Tuesday, April 17, 2018 4:54 PM
  • Hi

    I have a similar problem.

    Collection "Desktop" on a RDS-Server where all (AD-)users have rights 
    Deployed apps (under collection Desktop) where only single (AD-) users have rights.

    Problem: All users can access the deployed apps although only a few users have the right on the deployed app.

    Have you solved the problem - what was the Problem?


    Tuesday, August 13, 2019 12:12 PM