Re: Interactive Logon Prohibited on DC
- From: "Jeff Pitsch" <jeff@xxxxxxxxxxxxxxxxx>
- Date: Fri, 21 Oct 2005 13:07:31 -0400
What security policy did you change? what errors are in the event log? Is
there a TS license server up and running?
Jeff Pitsch
http://www.sbcgatekeeper.com
Your Terminal Services Security Website
"Marlon Velasco" <mvelasco@xxxxxxxxxxxxxx> wrote in message
news:OVRQw9c1FHA.3756@xxxxxxxxxxxxxxxxxxxxxxx
> Single Domain Environment:
> 1 - Windows 2000 SP4 AD/Terminal Server (1st DC)
> 1 - Windows 2000 SP4 AD/File Server (2nd DC)
>
> I just setup TS on the 1st DC (I know this is not recommended) but
> everytime TS users try to connect they get an error saying "The local
> policy does not permit interactive logons....". I changed the Domain
> Controller Security policy to include all the Terminal Server users and
> ran the secedit command as specified in the MS article regarding this
> error - same error. I even rebooted the server with the same results.
> Interestingly enough I am able to connect to the 2nd DC with any of the
> user accounts, although this is setup just as Terminal Services in Remote
> Admin mode. This tells me the domain controller policy should be working
> OK so it's got to be a setting on the 1st DC. Any ideas? I got around
> this temporarily by adding the TS users to the Server Operators group
> (also setup to open specific application to avoid access to desktop).
>
> Any ideas would be greatly appreciated.
>
> Thanks,
> Marlon
>
.
- Follow-Ups:
- Re: Interactive Logon Prohibited on DC
- From: Marlon Velasco
- Re: Interactive Logon Prohibited on DC
- References:
- Interactive Logon Prohibited on DC
- From: Marlon Velasco
- Interactive Logon Prohibited on DC
- Prev by Date: Re: Non-administrators in admin/maintenance mode
- Next by Date: Re: Help req: how to keep connection open after logout from ts session?
- Previous by thread: Interactive Logon Prohibited on DC
- Next by thread: Re: Interactive Logon Prohibited on DC
- Index(es):
Relevant Pages
|