Re: Domain Users group does not retain the Log on Locally right



Here is what happened just a few minutes ago. Removed an XP SP2 machine from
the SBS domain and joined a WORKGROUP. Rebooted. Deleted computer account
from AD using the SBS Console. Readded the computer account. Logged onto
that computer locally as Administrator. Ran \\servername\connectcomputer.
Computer reboot when completed. Logged onto the SBS Domain as administrator.
Went in the Local Policy Editor and cofirmed that DOMAINANME\Domain Users
were there. Great. This is what I expected and wanted to see. I then ran MS
Updates. Rebooted and logged back onto the SBS Domain as administrator. Went
back into the Local Policy Editor and the policy is now greyed out and
DOMAINNAME\Domain Users are no longer there.


"Dave Nickason [SBS MVP]" <gwdibble@xxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:uJ%23WAhUUHHA.5016@xxxxxxxxxxxxxxxxxxxxxxx
On an effected workstation, Start -> Run -> rsop.msc. You'll get a result
showing the group policies applied to that machine and user account.
Check for conflicting policies - if you find any, it'll tell you where
they are applied from so you can edit accordingly.


"AllenM" <noemail@xxxxxxxxxxxxx> wrote in message
news:%2306DDdUUHHA.1000@xxxxxxxxxxxxxxxxxxxxxxx
I've got some workstations here in the office that appear were not joined
to the SBS domain by using the SBS wizard. I discovered this when other
users were not able to log onto any machine in the office because "Domain
Users" were not members of the "Log on Locally" policy. So what I have
been doing is removing the workstation from the domain, deleting the
computer account from AD and then readding the computer account then
going to the workstations and logging in as local administrator and
running \\servername\connectcomputer.
My issues are that when I do this I go to check the local policy on the
workstations and it does add Domain Users to the Lo on Locally policy. So
now I run Windows and Microaoft Updates and have noticed that these
machines where I had to rejoin the domain are not retaining the Domain
Users group in the Log on Locally policy. In fact when I go to view the
policy and membership I can see the members but now they are all greyed
out and I cannot manually edit them. So it appears that updates are
somehow affecting this process. Any ideas? I have checked my Domain GPO
and yes Domain Users are in the Lo on Locally domain policy.





.



Relevant Pages

  • Re: Machine Policy not being applied
    ... I'm not totally clear on what you're doing but for the machine settings to ... the computer account must be in the OU to which the policy is ... > I added the template to the Default Domain Policy - IT WORKED FINE. ...
    (microsoft.public.win2000.group_policy)
  • RE: Remote Installation Services, DoOldStyleDomainJoin=Yes
    ... It appears that the policy had been set previoulsy but when the policy was ... > SP1 introduced additonal RPC and SAMR security and during the upgrade SP1 ... > updates that SP1 will be over written and thus the workstation will not have ... >> provide domain account credentials to join the computer account to the ...
    (microsoft.public.windows.group_policy)
  • Re: Domain Users group does not retain the Log on Locally right
    ... successfully completed but after the updates the Domain Users disappeared. ... Users" were not members of the "Log on Locally" policy. ... computer account from AD and then readding the computer account then ... workstations and it does add Domain Users to the Lo on Locally policy. ...
    (microsoft.public.windows.server.sbs)
  • Re: Assigning/Publishing Office 2003 in Active Directory
    ... Forgot about the computer account moving to the OU. ... or you must apply the GPO to the computer through the Apply Policy ... > Any ideas why this is not installing? ...
    (microsoft.public.win2000.active_directory)
  • Re: all employees logging into all workstations
    ... You need the clients ability to log on to each computer in the SBS domain. ... Locate the User Rights Assignment settings under the Local Policy node. ... Microsoft Online Partner Support ...
    (microsoft.public.windows.server.sbs)