RE: Log on Locally problems

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Mike Gallagher (MikeGallagher_at_discussions.microsoft.com)
Date: 11/01/04


Date: Mon, 1 Nov 2004 12:06:04 -0800

Thanks for the reply. The domain controller security policy allows this user,
and the server op group the log on locally right. That is what has me so
puzzled.

Mike

"Bob Smith" wrote:

> If you are running Windows 2000 DC's then you need to modify the Domain
> Controllers Policy applied to the Domain Controllers OU. The Domain
> Controllers policy is locked down to control access to your most secure
> servers in the environment (your DC's). you need ot open up the policy and
> add permissions for her to log on (I would do this through a group). It
> should be under Machine Policy\User Rights Assignment\Log on locally or
> something (Don't have a 2k environment here to look at it exactly).
>
> Then use the secedit /refreshpolicy machine_policy /enforce to all the DC's
> if you don't want to wait the default 15 minutes.
>
> As for your other issues... I don't really know.
>
>
>
> "Mike Gallagher" wrote:
>
> > Hello All,
> > We are having some problems and I'm starting to get really confused. The
> > problems all lead me back to the same issue when I research them, but I hit a
> > dead end. We have 4 domain controllers. 2 are at our main site, and 1 each at
> > our 2 remote locations.
> >
> > The main problem I am writing about is that we have a new member of the IT
> > dept that is our web site admin. She needs to log on to one of our DCs to do
> > admin work on our Intranet site. She is not a domain admin so it will not let
> > her. I put her in the "server operator" group, and it still will not let her.
> > I gave both her account, and the server op group "log on locally"
> > permissions, but that hasn't worked. Only domain admins can log on locally to
> > the server.
> >
> > Here is another problem that makes me think it is related. Our 2 remote
> > locations, in addition to being DC also are backend servers for Exchange.
> > Only domain admins can access OWA on those 2 servers. I created a test web
> > site, and the same thing happened. This makes me believe that the issue is
> > with Windows and not Exchange. The strange part about the test web site and
> > OWA is that if a domain admin logs on to the web site, for about 5 minutes
> > all users can authenticate just fine. Then it starts denying them again.
> >
> > Finally, when I first installed the 2 servers at the remote sites we had an
> > issue where only domain admins could print. I changed the printers from
> > queueing to print directly, and it worked. Since I had time restraints, and
> > there are only a few users at these locations I let it go. However, now the
> > other makes me think this is a larger issue. For both the printing and the
> > web sites the NTFS permissions are fine. And in the domain and local security
> > policies the "authenticated users" group has log on locally and access from
> > the network permissions.
> >
> > Sorry to ramble but the issues all seem related, and people are starting to
> > complain.
> >
> > Thanks
> > Mike



Relevant Pages

  • Re: Re: Event IDs 1030 & 1058 (again)
    ... Controllers container. ... "Domain Controller Security Policy". ... appear by default on Windows Server 2003. ... >> Windows Platform Support Team ...
    (microsoft.public.windows.group_policy)
  • Re: How to allow users to create groups and shares
    ... Add the user/group to the Computer configuration, windows settings, security settings, Local policies, "Allow logon locally" in the Default domain controllers policy and on a existing or new created policy for the member servers. ... Filtering: Not Applied ... check with GPMC on the server or from a client the policy settings. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Can not log on to domain controller remotely or locally.
    ... Be aware that the higher you place this setting within the domains group policy the possibility exists it is applied to machines you may not want it applied to. ... With this in mind you should try and avoid this setting at the domain level, with the exception on the domain admins group. ... policy since the default Server 2003 password policy is pretty harsh. ...
    (microsoft.public.windows.server.active_directory)
  • UserEnv errors, Default DC Policy related
    ... I am experiencing an error with a single server related to the Default Domain ... a gpresult on this server shows that the default domain controllers ... Computer Group Policy results for: ... Last time Group Policy was applied: Thursday, June 07, 2007 at 9:04:26 AM ...
    (microsoft.public.windows.server.active_directory)
  • Re: Logon through terminal services
    ... However, when I put the information and tries to logon, it tells me: ... Policy to allow logon through terminal services, ... The server is a Small Business. ... If I give domain admins privilege to the user, ...
    (microsoft.public.windows.terminal_services)