"The local policy of this system doesn't permit you to logon interactively" on workstation

From: Darius Mikalauskas (darius_at_lightcon.com)
Date: 07/27/04


Date: Tue, 27 Jul 2004 13:29:16 +0300

We have 12 computers in our SBS2003 network.
>From some moment no one except administrator can logon locally to two
workstations. One workstation is Windows2000 and another Windows XP
Professional.
All users except administrator get this error: "The local policy of this
system doesn't permit you to logon interactively".
There is no problems for all users on other computers.

I checked local policy on one of the workstations:

log on locally (read only): IUSR_SERVER, IUSR_COMPUTER, Administrators,
*S-1-5-32-548, *S-1-5-32-549, *S-1-5-32-550, Backup Operators
Deny logon locally (read only): DOMAIN\SUPPORT_388945a0, DOMAIN\SBS Remote
Operators, DOMAIN\SBS STS Worker

"Group policy results" on this computer from the Group policy management
console on server:
Allow log on locally: Print Operators, Server Operators, Acount Operators,
Backup Operators, Administrators, IUSR_SERVER (winning GPO Default
Domain Controllers Policy)
Deny logon locally: DOMAIN\SUPPORT_388945a0, DOMAIN\SBS Remote Operators,
DOMAIN\SBS STS Worker (winning GPO Default Domain Controllers Policy).

Please can you help.
Best regards

Darius



Relevant Pages

  • Re: Active directory Group Policy (Win2k)
    ... When I enforce the policy onto the computers in the new OU, ... Domain Admins so the Domain Admins cannot view ... workstations, to access Microsoft Office. ...
    (microsoft.public.security)
  • Re: group policys
    ... are you wanting the workstations to lock the session if the user walks away? ... I created my own policy. ... > this.(Microsoft Network Server: Amount of idle time before suspend ... >> then My Business and then Computers and then SBS Computers and in here ...
    (microsoft.public.windows.server.sbs)
  • Re: better way to limit users/group to logon to specific workstations?
    ... Apply this policy to an OU where the computers are. ... We limit a set of user accounts to logging on to specific workstations by ...
    (microsoft.public.windows.group_policy)
  • Re: Easy question on the local admin passwords
    ... As Joe said if the user has system or administrator access he already owns ... the operating system and yes that can pose a problem in some cases. ... could do is make sure that those computers to not use the Group Policy ... password on the laptops than the workstations. ...
    (microsoft.public.win2000.security)
  • Re: User group assigned to OU of computers for...
    ... workstations to the domain" only applies to settings in the domain ... controller level security policy and is ignored at any other level. ... to a user without being an administrator, such as managing users/groups, ... computers for an OU using "restricted groups" if need be. ...
    (microsoft.public.win2000.security)

Loading