Re: Server 2003 Local Login

From: Chriss3 [MVP] (noSpamHere_at_chrisse.se)
Date: 10/12/04


Date: Tue, 12 Oct 2004 18:45:52 +0200

No that's not possible, only domain accounts can be used for logon at DCs,
local accounts or groups dose not exist on DCs.

-- 
Regards
Christoffer Andersson
Microsoft MVP - Directory Services
No email replies please - reply in the newsgroup
------------------------------------------------
http://www.chrisse.se - Active Directory Tips
"Mike" <Mike@discussions.microsoft.com> skrev i meddelandet 
news:B04BFCA2-474C-46A8-8305-494064F1B4DC@microsoft.com...
>I have looked at the local policy and as you mentioned administrators are
> allow to logon locally.  How do I login as the local admin and not a 
> domain
> admin or user authenticated to AD users and computers?  Is this possible?
>
> "Chriss3 [MVP]" wrote:
>
>> Hello Michael,
>> The Local SAM Database is disabled when the computer become a domain
>> controller, the same behavior in Windows 2000 Server. You have to modify 
>> the
>> Allow Logon Locally within the Default Domain Controllers Policy or 
>> another
>> Group Policy effecting the particular DC.
>>
>> You can always logon to a DC using the administrator account, or an 
>> account
>> member of the domain admins in the particular domain.
>>
>> -- 
>> Regards
>> Christoffer Andersson
>> Microsoft MVP - Directory Services
>>
>> No email replies please - reply in the newsgroup
>> ------------------------------------------------
>> http://www.chrisse.se - Active Directory Tips
>>
>> "Michael.Gatt" <MichaelGatt@discussions.microsoft.com> skrev i 
>> meddelandet
>> news:2F462EFF-ED54-4821-8E84-4887F6BC7A8A@microsoft.com...
>> >I have a Server 2003 Domain Controller and I would like to know if it is
>> > possible to login locally?  Before upgrading to a DC I was given the
>> > option
>> > of the Domain which the Server was a member of and "This Computer". 
>> > Since
>> > it
>> > became a DC the "This Computer" option is gone.  I have tried Safe Mode
>> > too
>> > but its also gone from there.  I do not remember Server 2000 removing 
>> > this
>> > option.
>> >
>> > Without network access I cannot login.  Does anyone know if there is a 
>> > way
>> > around this in Server 2003?
>> >
>> > Thank you!
>>
>>
>>