Local Policy Prevents Login Interactively

From: Michael Cooper (mcooper06_at_yahoo.com)
Date: 10/04/04


Date: Mon, 4 Oct 2004 16:12:51 -0700


Upgraded a Windows NT 4.o domain to Win2K03. Also had a
Citrix server that was Win2K. Had to promote Citrix
server to BDC so that Terminal Services Licensing would
work. All seems fine now with service but non Admin users
get error message at login that "local policy prevents
them from loggin in interactively". I get the same error
at either the console or through a Terminal Logon.

I have checked the following:

Local Security Policy has Authenticated Users in:
Security Settings..Local Policies..User Rights
Assignment.."Log On Locally"

Domain Controller Policy has Authenticated Users (and
Users) in:
Security Settings..Local Policies..User Rights
Assignment.."Log On Locally"

If I make a change to the Domain Controller Policy (it
seems any arbitrary change) and then use secedit to force
the update, the non-admin users can suddenly login fine
with GPO's applied as they should be. If I give it time
(15-20 minutes) for Group Policy to update, I am back to
where I started.

HELP!

Michael Cooper



Relevant Pages

  • Re: Setup RDP to a windows 2003 domain controller
    ... enable in the Default Domain Controller Policy: ... "Allow log on through Terminal Services" ... and add the Remote Desktop Users group to the list of allowed users ... MCSE, CCEA, Microsoft MVP - Terminal Server ...
    (microsoft.public.windows.terminal_services)
  • Re: Default Domain Policy
    ... If you look at your default domain controller policy, ... It is the "managing audit and security log" user right. ... user rights assignments and security options sections before you restore. ...
    (microsoft.public.windows.group_policy)
  • Re: How to stop all authenticated users from adding computers
    ... default domain controller policy or equivalents for the security right "ADD WORKSTATIONS TO DOMAIN". ... I assume Domain users or Everyone are listed there. ...
    (microsoft.public.windows.server.active_directory)

Loading