RE: I shot my foot off almost and the Admin can't log into the server locally

From: Matt Trudewind[MSFT] (a-mattt_at_online.microsoft.com)
Date: 03/29/04


Date: Mon, 29 Mar 2004 20:46:22 GMT


--------------------
>
>Looks like you're not trying to logon locally at the
>console, you're logging on locally through an Internet
>Service/Application of some kind?
>
>127.0.0.1 may not be a member of the "Trusted"
>or "Intranet" zones.
>
>If that does not fit your situation, then pls repost
>exactly how you are trying to "logon locally," througn
>what interface/application.
>
>Tony Su
>
>
>
>
>>-----Original Message-----
>>Prior to today, the Adminnistrator account has been able
>to log in locally to the SBS 2003 server. (Let's not
>debate the merits of that.) I was screwing around on
>client pc's adding them to the server, etc, and now when I
>attempt to log into the server I get the infamous you are
>not allowed to log on locally message. Here are the
>details from the event log:
>>Logon Failure:
>> Reason: The user has not been granted the requested
>> logon type at this machine
>> User Name: Administrator
>> Domain: 3BEARS
>> Logon Type: 2
>> Logon Process: User32
>> Authentication Package: Negotiate
>> Workstation Name: AC2M2
>> Caller User Name: AC2M2$
>> Caller Domain: 3BEARS
>> Caller Logon ID: (0x0,0x3E7)
>> Caller Process ID: 432
>> Transited Services: -
>> Source Network Address: 127.0.0.1
>> Source Port: 0
>>
>>Two things are good
>>1. The Administrator account can still log on to the
>server from another PC on the netwrk.
>>2. I have a back up administrator and that works fine.
>>
>>I've tried many of the suggestions here and nothing seems
>to help.
>>
>>The only interesting thing that I saw was
>that "administrator" was missing from account on the
>Administrator's Proerty Page Account tab. Restoring that
>did not help.
>>
>>I've been all through both the local policies and group
>policies and have not spotted anything.
>>
>>Any more suggestions would be appreciated. I'll
>cheerfully report back on what I find.
>>
>>Regards,
>>Al
>>.
>>
>

Login with your other Admin account and check group membership of the Administrator account.

By default the Administrator should be a member of these groups:

Administrators, Domain Admins, Domain Users, Enterprise Admins, Group Policy Creators, Internet Users, Mobile Users, and Schema Admins.

If the Administrator is a member of any additional group then go ahead and remove him from those.

Matt Trudewind
Microsoft Product Support Specialist
This posting is provided "AS IS" with no warranties, and confers no rights.



Relevant Pages

  • Re: Login as local admin
    ... So if i basically ensure that my domain administrator account is a member of ... the schema admins, and enterprise admins, and login using these credentials, ... The article does not reference "local" administrator (as far as I ... If you choose to use an account other than the built-in administrator ...
    (microsoft.public.windows.server.sbs)
  • Re: Login as local admin
    ... schema admins, enterprise admins and the other groups mentioned, but the ... installing SBS SP1. ... So if i basically ensure that my domain administrator account is a member ... The article does not reference "local" administrator (as far as I ...
    (microsoft.public.windows.server.sbs)
  • Re: Login as local admin
    ... schema admins, enterprise admins and the other groups mentioned, but the ... So if i basically ensure that my domain administrator account is a member ... The article does not reference "local" administrator (as far as I ... As i am trying to install SBS SP1, ...
    (microsoft.public.windows.server.sbs)
  • Re: Upgrade SBS2000 to SBS2003
    ... Specify an account with Enterprise Administrator prrivileges to the ... The domain Administrator account should be a member of the Enterprise ... Enterprise Admins" error when you run the Windows Small Business ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Internet Explorer and index.dats
    ... I use a batch file that runs at boot. ... > So if my user account is reflected in the administrators account, ... >> the internal "Administrator" account. ... >> since if you delete the Temporary Internet Files via the Windows ...
    (microsoft.public.windowsxp.customize)