Re: Can't login interactively after domain rename

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 05/18/04


Date: Tue, 18 May 2004 01:48:02 -0700

Evidently Domain Users is not in Users on those machines,
or, other changes have occurred to effect the Domain Users
no longer being granted "Log on locally" user right on the
workstations. Check the values in the effective policies on
those workstations, for the policies in the User Rights section
for Log on locally, and Deny local logon.

The message you cite shows that their accounts are being
recognized, and so the workstation is correctly joined into
the renamed domain.

-- 
Roger Abell
Microsoft MVP (Windows Server System: Security)
MCSE (W2k3,W2k,Nt4)  MCDBA
"Brett" <bmoffitt@iastate.edu> wrote in message
news:e51c01c43c64$c0945800$a601280a@phx.gbl...
> As a member of the users group, if I try to logon to any
> workstation in the domain, I get a message saying "The
> local policy of this system does not permit you to logon
> interactively."  If I logon with Domain Admin credentials,
> I have no problems.  I'm trying to figure out what I did.
> I recently went through a domain renaming process and used
> the dcgpofix tool to restore the default GPO but not
> luck.  The only other solution I can think of is to do a
> DCPROMO and start from scratch.
>
> (Please copy replies to my email address:
> bmoffitt@iastate.edu)


Relevant Pages

  • RE: Event ID 529
    ... The source is clear - workstations that are not part of my ... SBS2003 domain share the same local network (it's a shared local network in ... This kind of issue may be caused by Application logon such as while Outlook ... is connecting to Exchange Server, or this is an automated dictionary attack ...
    (microsoft.public.windows.server.sbs)
  • Re: How do manage your workstations?
    ... For the most part these functions require a local administrator rights. ... Therefore I have to logoff the regular user, then I logon as local administrator so I can update programs or add-in devices. ... However, if there are hundreds of workstations involved, it’s really time consuming! ... Maybe there is remote installation system that push program updates to the workstation and that system logons on as domain admin. ...
    (microsoft.public.windowsxp.general)
  • Re: "Lock workstations" after certain idle time. Is it advisable to do it from server side
    ... > business needs, ... > to mitigate the risk of unauthorized access. ... > unlocked terminal or even a logon prompt without a warning can be ... >> workstations idle for a certain period of time. ...
    (microsoft.public.win2000.active_directory)
  • Re: Restricting network Logins
    ... Since you're on a 2003 domain, I'll assume your workstations are either ... Computers has an old left-over from the Windows NT days - "Logon To" on the ... NetBIOS name to the "Logon To..." ... >> simply enable passwords on the user's accounts on each PC. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Upon Startup, Welcome Screen nevers reaches logon selection.
    ... Microsoft MVP (Windows Server System: Security) ... Both in Normal Mode and in Safe ... I cannot reach a screen to logon. ...
    (microsoft.public.windowsxp.security_admin)