***Screwed the Pooch...PLEASE HELP***



I have googled the groups and the MS KB, and there is NOTHING out there
that addresses this problem with a clear cut solution.

1- I am running SBS2003 as a domain controller.
2- I used GPO editor to edit the default domain client computer local
computer policy to allow a particular (non admin) user the right to
login locally on any system. (to allow him to use RDP, which worked)
3- However, I did not think that the local computer policy GPO would
ALSO apply to the server...it is not a client computer. Of course, it
did. Now, because I did NOT add the domain admin to the list of users
with login locally right, the domain admin can no longer log into the
system. The user i DID grant the right to is not an admin and 2003SBS
will not let him login locally.

OMG I am so screwed. I admin this system remotely, never had this
problem and I am completely unequipped to deal with it.

~tia

.



Relevant Pages

  • Re: ***Screwed the Pooch...PLEASE HELP***
    ... workstation then connect to Active Directory and disable the GPO. ... > computer policy to allow a particular (non admin) user the right to ... > ALSO apply to the server...it is not a client computer. ... because I did NOT add the domain admin to the list of users ...
    (microsoft.public.windows.server.sbs)
  • RE: software to control domain administrators
    ... these so-called controls on the admin. ... what would you do when you need that level of control. ... admin changed the domain admin password when he or she found out that they ... software to control domain administrators ...
    (Security-Basics)
  • Re: Finding a Hacker
    ... compromising the loca or domain admin acocunts, or by elevation, ... to get local admin rights on the machine used by the domain admin, ... If the hacker did get in remotely using an administrator account on ... Your problem is not restricting remote desktop connections. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Local rights question
    ... How to make a user an admin of his PC. ... > connectcomputer wizard on the workstations. ... Join the client computer into the SBS domain. ... > Since you have already manually joined the workstation into the current ...
    (microsoft.public.windows.server.sbs)
  • Re: Security Filtering does not work correctly in GPO
    ... administrator object for this GPO. ... I deleted the domain admin profile on the ... where the domain admin was logged on. ... I will now keep track on it, if the administrator receices the settings again. ...
    (microsoft.public.windows.server.active_directory)

Loading