A freshly created domain user cannot open a Remote Desktop session to a domain-joined PC ("not authorized for remote login"). Why, and how is it fixed at scale?
Remote Desktop logon is only allowed for members of the PC's local Administrators or Remote Desktop Users group, and the new user is in neither. The fix is a GPO that puts the right domain group into that local group on every PC.
Every Windows machine has its own local groups, separate from AD. Being a valid domain user lets you log on at the console, but RDP additionally requires the right "Allow log on through Remote Desktop Services", which by default only those two local groups have.
Adding the user to Remote Desktop Users by hand works for one PC, but not for hundreds. So a computer GPO (Restricted Groups) manages the membership of the local group centrally, and every machine in the linked OU picks it up.
Go deeper:
Microsoft Learn: Allow log on through Remote Desktop Services โ the user right behind the error, and its defaults.