local policy does not allow user to logon interactively.


hi all,

 

i looking guidance.

 

when user tries log xp based computer opposed logging on domain, receive error local policy not allow them logon interactively.

 

according article found there may group policy prohibits this. here article: http://articles.techrepublic.com.com/5100-10878_11-5313668.html

 

but there no group policy on domain level prohibits this.

 

i’d set domain based group policy permit local power users , local administrators log on computer locally. administrator can log on locally.

 

is can done way of domain based group policy? if so, can point me in direction of solution?

 

many thanks!!!

 

lebby 

hi,

verify gpos applied computer (say, via site, domain, ou or local policy). may need check local policy if setting not configured in of other policies. check groups/accounts specified in "deny logon locally" group policy setting.

if allow power users , administrators rights login locally, no other accounts (except members of these 2 groups) can log on computers.

you have configure user rights assignments in gpo set settings. go following location in gpo set configuration:

computer configuration\windows settings\security settings\local policies\user rights assignment

for description of each setting in gpo branch, please refer following technet article:

regards,

salvador manaois iii
mcse mcsa mcts mcitp c|eh ciwa
----------------------------------------------------------------------------
bytes & badz: http://badzmanaois.blogspot.com
my passion: http://flickr.com/photos/badzmanaois
my scripting blog: http://sgwindowsgroup.org/blogs/badz


Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS