Discussion:
Local policy does not allow you to logon interactively
(too old to reply)
j***@gmail.com
2005-11-22 17:00:37 UTC
Permalink
I am setting up a w2k server that is a domain controller and a term
server. I am getting an error at logon that says that the local policy
does not allow you to logon interactively. I know that the local
policy has to be set to allow local logon for a group that the account
is a member of and that has been done. I have other servers that are
set up the same way and they work. I have a group called terminal
users and grant the right to logon locally to that group. I am using a
few test accounts and they can logon to all of the existing servers,
but not the new one. I have a second server that I am setting up and I
installed TS before running dcpromo. The test accounts have no
problems logging on to the new server that is not a dc. I think it has
something to do with group policy or local policy or even domain
controller policy, but I cannot find the issue. Has anyone seen this
before? Any solutions?
Vera Noest [MVP]
2005-11-22 20:30:32 UTC
Permalink
I assume that you know that running Terminal Services in
Application Server mode is *not* recommended on a Domain
Controller, for both performance and security reasons?

You will have to modify the Default Domain Controller Security
Policy to allow your users the "Log on Locally" right to your
domain controllers.

246109 - Error Messages Generated When Logging on with Terminal
Services Client
http://support.microsoft.com/?kbid=246109
_________________________________________________________
Vera Noest
MCSE, CCEA, Microsoft MVP - Terminal Server
TS troubleshooting: http://ts.veranoest.net
___ please respond in newsgroup, NOT by private email ___
Post by j***@gmail.com
I am setting up a w2k server that is a domain controller and a
term server. I am getting an error at logon that says that the
local policy does not allow you to logon interactively. I know
that the local policy has to be set to allow local logon for a
group that the account is a member of and that has been done. I
have other servers that are set up the same way and they work.
I have a group called terminal users and grant the right to
logon locally to that group. I am using a few test accounts and
they can logon to all of the existing servers, but not the new
one. I have a second server that I am setting up and I
installed TS before running dcpromo. The test accounts have no
problems logging on to the new server that is not a dc. I think
it has something to do with group policy or local policy or even
domain controller policy, but I cannot find the issue. Has
anyone seen this before? Any solutions?
j***@gmail.com
2005-11-23 15:17:48 UTC
Permalink
Thanks Vera. I do know that this is not a recommended practice, but I
can not justify 2 boxes to support a handful of users.

I ended up demoting it, pulling it out of the domain, adding it back to
the domain, and promoting it. It works like a champ now. It must have
had some issues with the domain policy. I used secedit to refresh the
policy, but that didn't do anything for me. Isn't there some tool that
will allow you to dump all of the policies on a machine and reapply
them rather than just refreshing them? I feel like I took the long way
around the barn...

Loading...