Why 'allow log on locally" is not configured by default??







HI,

I am learning Ms Active Direcotry the moment. But i am a bit confused
why we would stop user to log on to
domain controller. Isn't all user in windows network implemented with
AD need to log on to server for authtication purpose? I can't think
about a any situation this not the case. Can anyone help me to clear
off this concept.
sybex: 70-290 pg 142
"NOrmally you don't want regular users to log on to domain controllers
so this actions isn't allowed by defult.

thx in advance
chris

.