remote desktop problem

From: Chris Nagle (ChrisNagle_at_discussions.microsoft.com)
Date: 02/22/05


Date: Tue, 22 Feb 2005 05:25:03 -0800

Ever since I upgraded my workstations to XP from 2000, I have not been able
to connect thru RDP (either locally from the server console or RWW). The
error is "The local policy does not permit you to logon interactively"

I can connect with the XP machines that were already XP when I joined them
to the SBS domain. The users that logon to the domain are a part of the
mobile users template. Here are my settings.

On the workstations in question: Remote users are Administrator and
DOMAIN\Administrator
User accounts---> DOMAIN\Administrator belong to the Administrators group
membership.
Advanced User Management---> Admnistrator (local) is a member of
Administrators and remote desktop users.
Admistrator group contains local admin and DOMAIN\administrator.

Group policy (local) user rights assignments
logon through Terminal Services = (blank)
Deny logon locally= support_389945a0
Deny logon through Terminal Services=(blank)
Logon Locally=DOMAIN\Administrator, Guest, Administrators, Users, Power
Users, Backup Operators.

Please note that all other functions work perfectly. I see no errors in the
local event logs. Also, when I try to logon to the workstations, I have tried
with the user logged off as well as on with no luck.

Any information would be appreciated.



Relevant Pages

  • RE: Event ID 529
    ... The source is clear - workstations that are not part of my ... SBS2003 domain share the same local network (it's a shared local network in ... This kind of issue may be caused by Application logon such as while Outlook ... is connecting to Exchange Server, or this is an automated dictionary attack ...
    (microsoft.public.windows.server.sbs)
  • Re: How do manage your workstations?
    ... For the most part these functions require a local administrator rights. ... Therefore I have to logoff the regular user, then I logon as local administrator so I can update programs or add-in devices. ... However, if there are hundreds of workstations involved, it’s really time consuming! ... Maybe there is remote installation system that push program updates to the workstation and that system logons on as domain admin. ...
    (microsoft.public.windowsxp.general)
  • Re: "Lock workstations" after certain idle time. Is it advisable to do it from server side
    ... > business needs, ... > to mitigate the risk of unauthorized access. ... > unlocked terminal or even a logon prompt without a warning can be ... >> workstations idle for a certain period of time. ...
    (microsoft.public.win2000.active_directory)
  • Re: Cant login interactively after domain rename
    ... those workstations, for the policies in the User Rights section ... for Log on locally, and Deny local logon. ... Microsoft MVP (Windows Server System: ...
    (microsoft.public.windows.group_policy)
  • Re: Restricting network Logins
    ... Since you're on a 2003 domain, I'll assume your workstations are either ... Computers has an old left-over from the Windows NT days - "Logon To" on the ... NetBIOS name to the "Logon To..." ... >> simply enable passwords on the user's accounts on each PC. ...
    (microsoft.public.windowsxp.security_admin)