local policy does not allow user to logon interactively.
hi all,
i looking guidance.
when user tries log xp based computer opposed logging on domain, receive error local policy not allow them logon interactively.
according article found there may group policy prohibits this. here article: http://articles.techrepublic.com.com/5100-10878_11-5313668.html
but there no group policy on domain level prohibits this.
i’d set domain based group policy permit local power users , local administrators log on computer locally. administrator can log on locally.
is can done way of domain based group policy? if so, can point me in direction of solution?
many thanks!!!
lebby
hi,
verify gpos applied computer (say, via site, domain, ou or local policy). may need check local policy if setting not configured in of other policies. check groups/accounts specified in "deny logon locally" group policy setting.
if allow power users , administrators rights login locally, no other accounts (except members of these 2 groups) can log on computers.
you have configure user rights assignments in gpo set settings. go following location in gpo set configuration:
computer configuration\windows settings\security settings\local policies\user rights assignment
for description of each setting in gpo branch, please refer following technet article:
http://technet.microsoft.com/en-us/library/cc780182(ws.10).aspx
salvador manaois iii
mcse mcsa mcts mcitp c|eh ciwa
----------------------------------------------------------------------------
bytes & badz: http://badzmanaois.blogspot.com
my passion: http://flickr.com/photos/badzmanaois
my scripting blog: http://sgwindowsgroup.org/blogs/badz
Windows Server > Security
Comments
Post a Comment