The local policy of this system does not permit you to logon interactively??

In Windows 2000 (and Windows Server 2003) servers that are configured as Domain Controllers only 5 groups have the right to log on locally on the computer. Those groups are:

Administrators, Account, Print, Backup, and Server Operators.

Without this right any user who will try to log on locally will receive this message:

(The local policy of this system does not permit you to log-on interactively)

To give a specific user or group the right to log on locally on the DC you must edit the Domain Controller GPO (or create another one and link it to the Domain Controllers OU in Active Directory Users and Computers). Most novice IT personnel find it harder to add user rights on W2K than in Windows NT 4. I agree, but life goes on, doesn't it?

To make life easier run this command and you won't have to edit the GPO:

ntrights -u Users +r SeInteractiveLogonRight

You must have the NTRIGHTS.EXE program from the W2K Resource kit (or d/l it from HERE).

(You can substitue USERS with the name of the user or group you want to configure).

If you still want to do it via the GPO, do the following:

  1. Go to Start, Settings, Control Panel, Administrative Settings.

  2. Double-click Domain Controller Security Policy.

  3. Go to Security Settings, Local Policies, User Rights.

  1. Double-click Logon Locally on the right pane.

  2. Click Add, Browse, and double click the user or group you want to add.

  1. Click Ok all the way out.

  2. Reboot your computer, or even better, use SECEDIT:

secedit /refreshpolicy machine_policy /enforce

By the way, in Windows Server 2003 the same user right is called "Allow Logon Locally", and to refresh the policy you need to run a different command:

gpupdate /force

 

Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Posted by calejo on Thursday, April 03, 2008 3:57 AM
E-mail | Bookmark and Share
Permalink | Comments (0) | Post RSSRSS comment feed

About me

Me

Hi, my name is Ricardo Calejo, currently working in the BMO Task Force Team of Microsoft Portugal, recent graduate of Instituto Superior de Engenharia do Porto in Computer Engineering and former Microsoft Student Partner. I also write in "A Posteriori" about music and thoughts.

"We all die! The goal isn’t to live forever, the goal is to create something that will."

Search


You might need


Archive


Tags


Categories


Blogroll

Download OPML file OPML

A Posteriori

411 - On my knees
The number 7 is arriving...
DJ Jay Cee - Turn the tide
Hercules & Love Affair - Blind
A Fine Frenzy - Almost Lover
Tiesto f/ Banyan Tree - Feel the Sun Rise
Just a see you soon!
Sam Sparro - Black & Gold
Robert Miles - One and one
Fingertips - Before and after Us
Lene Marlin - Maybe I'll go
Schiller - I've seen it all feat Maya Saban
ATB - Let U Go (Reworked)
Muse - Unintended
Plumb - In my arms
Jack Savoretti - Dreamers
Adele - Hometown Glory
James Blunt - I really want you
Stereophonics - Dakota
Schiller - I Saved You & Schiller - Forever || feat Kim Sanders

ClustrMaps

Locations of visitors to this page

Disclaimer

The opinions expressed herein are my own personal opinions and do not represent my employer's view in anyway.

© Copyright 2008

Asp .net © 2007 Ricardo Calejo ® Todos os Direitos Reservados