Re: Error "the local policy of this system does not permit..



"aznan" <aznan@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:289D9DE2-2E3C-4D6A-BB54-20D4BE4DCFC6@xxxxxxxxxxxxxxxx
Hi, i'm having problem with the local user account.

We're running Windows 2000 Domain Server with Active Directory , all users
logon to their PCs using their NT Login ID which authenticates through our
Domain but however i still need to create a "local" user account for each
PC
with "Power user" rights.

Why? It is generally a mistake to create any local
users except for perhaps housekeeping or some
services.

Domain users & local Administrator can logon without any problems but only
when i create a local account named "primary" with power users rights it
denies the logon with an error message "The local policy of this system
does
not permit you to logon interactively"

Power Users is a GROUP not a "right".

You created a User named Primary on a workstation but that
user cannot logon when pressing Ctrl-Alt-Delete and using
the name User with the "domain" set to the "Computer Name"?

Is this precisely correct?

It works fine if i give "Administrator" rights for this local account but
i
have to restrict this user account from having full access to the system.

Is there anything from the Domain "Local Security Settings" that's denying
it or... how can i permit this local account to logon locally

This isn't a Server (OS) machine is it?

--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]


Please help/advise

Aznan
The International School of Penang (Uplands)


.



Relevant Pages

  • Re: Limited Access
    ... For users that you want to logon to a computer via Remote Desktop you need ... Remote Desktop Users group. ... sharing to the computer not impeded by a firewall and the user account also ... On my desktop and wired laptop the hard drives are ...
    (microsoft.public.windowsxp.security_admin)
  • Re: GC Question
    ... The Domain and Forest Level are in 2003 ... Then i started up only the Dc for Child domain ... logon on that domain including in the Domain Controller for that Domain, ... When I try to create the user account "User01" I received the following ...
    (microsoft.public.win2000.active_directory)
  • Re: SBS re-connection
    ... I understand that you can not logon domain again ... Do you mean the issue disappeared if you delete the user account on ... >This newsgroup only focuses on SBS technical issues. ... you may want to contact Microsoft CSS directly. ...
    (microsoft.public.windows.server.sbs)
  • Re: Gaining Administrator Access to Windows XP Professional SP2 Sy
    ... Now an attacker could logon as ... If you export and delete your EFS ... and I did not create any Designated Recovery Agent ... simply change the passwords of every user account on the system, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Tracking unauthorized access to my computer
    ... Remote Desktop. ... The user name, logon type, and time can give you an idea who is ... Also look at your own logon events for your user account ... I would also increase the size of the security log to like ...
    (microsoft.public.security)

Loading