Local administrator cannot logon locally

R

Ringo

A win2k member server cannot logon locally using local
administrator. When I check "logon locally" policy, all
the "effective policy" setting are dimmed for all users
except domain administrator. Only domain administrator can
logon to the member server right now. I tried to use the
ntrights.exe from resource kit to reset the logon locally
policy for local administrator and it get illegal
instruction. Can anyone help me to fix this. Thks.
 
G

Gary Mudgett [MSFT]

There is a policy in the domain that is overwriting the local policy
settings. You will need to find what policy it is coming from and modify or
"not define" so the local policy setting can take effect again.

Since you can logon as Domain Admin, if you have the resource kit you could
run GPRESULT and see what policies are applying Security Settings. Or look
through the OU structure path to where the computer account is for any
policies that are defining the "Logon locally" user right.

--
Gary Mudgett, MCSE, MCSA
Windows 2000/2003 Directory Services

=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top