Log On Locally Denied for Administrators Member

From: MCDBA Wannabe (anonymous_at_microsoft.news.net)
Date: 08/05/04


Date: Thu, 5 Aug 2004 09:57:16 -0400

I have run into a wall with this one. Here's the setup:

- Windows Server 2003 Cluster (2 nodes)
- Logon Locally restricted to local Administrators only
- Global group used to nest membership of Local Administrators group at the
domain level
- AD user account is a member of global group with admin access locally

When the user account is a granted access via the global group membership
logon locally is denied by the local policy. If the user account is
explicitly made a member of local Administrators group logon locally is
permitted. Test accounts have been created and do not have the same issue.

Any help is greatly appreciated!

-- 
Thanks!
______________________________________
Michael DiGiuseppe
Technical Services - Enterprise
North Carolina Department of Transportation
Century Center - Building B
______________________________________
E-mail correspondence to and from this address
may be subject to North Carolina Public Records
Law "NCGS.Ch.132" and may be disclosed to
third parties by an authorized state official.


Relevant Pages

  • Re: Log On Locally Denied for Administrators Member
    ... > - Global group used to nest membership of Local Administrators group at ... > When the user account is a granted access via the global group membership ...
    (microsoft.public.windows.server.clustering)
  • RE: Fax Preview Button
    ... Please use Add User wizard to add a new user, ... Client Computers wizard to add a new computer account, ... Remove the new user account from Local Administrators group, ...
    (microsoft.public.windows.server.sbs)
  • Re: Group Manipulation
    ... option for your new global group that contains the users that you want to be ... The computers that you want this to be enforced on ... Restricted Groups is configured. ... >> users being local administrators on all those computers keeping in mind ...
    (microsoft.public.windows.group_policy)
  • Re: Preserving Win XP User Settings when joining a Win2000 Domain
    ... Navigate to the new profile. ... if your old user account was a member of the local Administrators ... Only domain administrators group members are automatically added to ...
    (microsoft.public.win2000.networking)
  • Re: add domain account to local administrator group
    ... You can use Restricted Groups by either replacing current membership of the ... risk of adding that user/group to the administrators group for the domain. ... localgroup" command to add a user/group to the local administrators group to ...
    (microsoft.public.win2000.group_policy)