Re: What policy change did I (or my colleague) make and how do I fix i



Maybe you are no longer a member of the groups that are allowed access. If you
can run the support tool gpresult on any domain computer it will show what
domain groups you are a member of. That would be the most likely explanation if
other domain admistrators have access. Otherwise as Steven said there may be
another GPO linked to the domain controller container that is applying those use
rights. If no one can logon locally to a domain controller you will need to
change the user right settings from a non domain controller domain computer to
allow access.

Steve


"George Squillace" <GeorgeSquillace@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C862045C-B507-4E73-8BEA-4E6DF27A144D@xxxxxxxxxxxxxxxx
Greetings!

For some reason I cannot log on locally to my DCs. I have checked the
Default Domain Controller Policy...I am a member of the groups that ARE
ALLOWED Log On Locally, and there is no policy set for Deny Log On Locally. I
have also set up Allow Logon Through Terminal Services so I can RDP to my
Domain Controller but I cannot logon interactively.

Where in the heck did I hack something up?

Any insights would be MUCH appreciated.

-George


.



Relevant Pages

  • Re: Local Console Password & Network Passwords Different
    ... the administrator password from any domain workstation. ... >> From any domain controller you can run the support tool dcdiag to find ... From any domain computer you can ... Anyhow you do not need to logon to the PDC fsmo to change any ...
    (microsoft.public.security)
  • Re: Users Cant Logon to DC Computer
    ... Or you could simply add the user or a group that the user is a member of to ... REALLY is a need for a regular user to logon to a domain controller. ... a new user account will not be a member of any of these ...
    (microsoft.public.windows.group_policy)
  • Logon Scripts
    ... Windows 2003 which is a member of the domain controller. ... users on the member server to logon to the 2003 box locally. ...
    (microsoft.public.win2000.termserv.clients)
  • Re: Terminal Services Licensing Error Message.
    ... Windows 2003 which is a member of the domain controller. ... users on the member server to logon to the 2003 box locally. ...
    (microsoft.public.win2000.termserv.clients)
  • Re: Cannot logo to Win 2003 Enterprise 32-bit
    ... maybe it is misconfigured or it can not find the domain controller. ... domain computer must point to a domain controller running dns with the ... Active Directory domain in it's tcp/ip properties as preferred dns server ... you should be able to logon to the local computer [computer's name ...
    (microsoft.public.windows.server.networking)