Re: Error "the local policy of this system does not permit..



"aznan" <aznan@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:8E61BB91-F448-45D7-9E56-D76E193AF54A@xxxxxxxxxxxxxxxx
Hi, sorry... i think i'm not good in explaining and it seems like you're
confused with my question.

No, I got most of it, but you neglected to say this
was a SERVER OS.

I need to create a local user name for a backup reason.

Domain users are fine, only local users with Power User right can't logon
locally (which ends up with an error message "the local policy of this
system
does not permit...")

Yes , it's not a server (OS) i'm using Windows XP with SP2.


Give the user the right to logon. Normal users don't
typically have the right to logon locally at servers.

--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]


--
The International School of Penang (Uplands)


"Herb Martin" wrote:

"aznan" <aznan@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:289D9DE2-2E3C-4D6A-BB54-20D4BE4DCFC6@xxxxxxxxxxxxxxxx
Hi, i'm having problem with the local user account.

We're running Windows 2000 Domain Server with Active Directory , all
users
logon to their PCs using their NT Login ID which authenticates through
our
Domain but however i still need to create a "local" user account for
each
PC
with "Power user" rights.

Why? It is generally a mistake to create any local
users except for perhaps housekeeping or some
services.

Domain users & local Administrator can logon without any problems but
only
when i create a local account named "primary" with power users rights
it
denies the logon with an error message "The local policy of this system
does
not permit you to logon interactively"

Power Users is a GROUP not a "right".

You created a User named Primary on a workstation but that
user cannot logon when pressing Ctrl-Alt-Delete and using
the name User with the "domain" set to the "Computer Name"?

Is this precisely correct?

It works fine if i give "Administrator" rights for this local account
but
i
have to restrict this user account from having full access to the
system.

Is there anything from the Domain "Local Security Settings" that's
denying
it or... how can i permit this local account to logon locally

This isn't a Server (OS) machine is it?

--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]


Please help/advise

Aznan
The International School of Penang (Uplands)





.



Relevant Pages

  • Re: Problems with Domain Join for XPE FP2007
    ... If you logon to local account, are you able to get to domain resources using the same domain user account ... you can enable audit and logging on the server side and see why it is rejecting the client logon request. ... try to do a domain join, I'm getting various errors that prevent the ...
    (microsoft.public.windowsxp.embedded)
  • Re: Calling NetUserChangePassword for changing other user password
    ... I perform a logon via the function ... 'NetUserChangePassword' with the Target user... ... A server or domain can be configured to require a user ... group or the user can change the password for a user account. ...
    (microsoft.public.windows.server.networking)
  • Re: Please help refresh my memory on AD DC
    ... When I boot my Laptop I reach the Logon screeen for XP Laptop and here ... admin account to be able to Login so I can control it from the DC. ... A domain user can by default logon to any domain computer, except Domain controllers. ... A Server has websites already hosted on it in a Workgroup and now I ...
    (microsoft.public.windows.server.active_directory)
  • Re: Remote Server Management by Delegate
    ... Create a new user account - PersonAdmin, ... and have them log onto the server console with these ... Make the user a 'power user' from the SBS Management Console | Users ...
    (microsoft.public.windows.server.sbs)
  • Re: Logon Server Unavailable
    ... There are currently no logon servers available to service ... You use a office laptop to connect the office VPN, when you map a network ... you may receive this message: "This account is the ... The server is not configured for transactions"> "A domain controller for your domain could not be contacted" ...
    (microsoft.public.windows.server.networking)