I would start by digging into the RDP connection manager logs in the server, but I would suspect NLA is enabled and might be having issues communication to the DC. If the passwords have been reset on say the DC side (with change password on next loggon) or expired NLA will prevent a user from logging in due to the expire status or change password status. It's a chicken and egg problem.