Re: The local policy of this machine does not allow you to logon interactively

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Vera Noest [MVP] (vera.noest_at_remove-this.hem.utfors.se)
Date: 06/06/04


Date: Sun, 06 Jun 2004 15:26:03 -0700

A few comments:

* Dave runs SBS 2000, not 2003
* The right to logon locally can be given to *any* user or user
group, you don't have to be a member of the Administrators group
(but the Administrators group has this right by default).
* He has already given Everyone the right to logon locally
* SBS 2003 does not support Terminal Services (in Application
mode)
* Windows 2003 TS does *not* require the right to log on locally
(this has changed since W2K TS). Unless it runs on a Domain
Controller, of course, which it shouldn't).

Dave, you write that you have modified the Domain Group policy,
but you have to modify the Default Domain Controller Group policy.

 --
Vera Noest
MCSE, CCEA, Microsoft MVP - Terminal Server
http://hem.fyristorg.com/vera/IT
 --- please respond in newsgroup, NOT by private email ---

Mike Silverman <Noah.Body@nowhere.ca> wrote in
news:#vaef4ATEHA.1244@TK2MSFTNGP10.phx.gbl:

> Dave,
>
> When you have a Windows 2003 server (be it SBS or member
> server), and you install terminal services, in order for users
> to connect, they must be able to log on locally. This is
> granted through the 'allow logon locally' right. In SBS,
> because it is automatically a DC, in order for users to log on
> locally to a DC, they must be a member of the administrators
> group. There's no other way around it.
>
> Mike.
>
> dave wrote:
>
>> I fogot to add...all users also have rights to RDP-TCP.
>>
>> dave wrote:
>>
>>
>>>I am having trouble with our Windows 2000 SBS install. First of
>>>all, when we promoted this server to a domain controller (it is
>>>the only server in our domain), all the users were for some
>>>reason added to the domain admins group. This is a problem
>>>because now we are having problems with users shutting down the
>>>server because they are now able to see the "Shut Down" option
>>>instead of just the "Log off..." and "Disconnect" options. I am
>>>removing users from the domain admins group now, but when the
>>>users are removed, they can no longer get into Terminal
>>>Services. The get the message: "the local policy of this
>>>machine does not allow you to logon interactively"
>>>I checked the Domain Group policy and added the everyone group
>>>"access this computer from the network" and "log on locally"
>>>rights. I looked at the Local Computer Policy for the server
>>>and noone is denied access. What is the deal?



Relevant Pages

  • Re: local policy of this system does not permit you to logon interacti
    ... they get this error message ... When I add any user to the administrators group, ... to the SBS server, ever; ... Terminal Services on SBS - all you can use is Remote Desktop for admin ...
    (microsoft.public.win2000.general)
  • RE: Terminal Services
    ... I understand that you want to have staff log ... we cannot make SBS to work as terminal server. ... why you cannot find Terminal Services in Add/Remove Windows Components. ...
    (microsoft.public.windows.server.sbs)
  • Re: Fax modem for SBS 2008
    ... I have an old ZOOM 33.6K external modem connected to my SBS 2008 server. ... Dave never really has spelled out what his requirement is and what the one was that he tried that didn't work. ... Cris Hanna [SBS - MVP] ... A Microsoft Registered Partner ...
    (microsoft.public.windows.server.sbs)
  • Re: Please help me as I am clueless at this point!
    ... Terminal Services is disabled in Application mode in SBS. ... member server running Terminal Services. ... "The list of users and computers cannot be found.Make sure the client ...
    (microsoft.public.windows.server.sbs)
  • Re: File Shares over router to router VPN
    ... What's your goal here Dave? ... Merv Porter [SBS MVP] ... > One of my clients has an SBS2003 server at their office. ... > has a firewall/VPN router at his home as well. ...
    (microsoft.public.windows.server.sbs)