"local policy... does not permit you to logon interactively"

R

Rich Roller

(I posted this also on the MS partner newsgroups but since this one is public
I'm interested to see what peers might have to say...)

Window XP Pro SP2 client connecting to Windows Server 2003 domain:

All of a sudden, when trying to logon certain users from XP machine I now get
"The local policy of this system does not permit you to logon interactively".

But only certain users have problem. Users who are Domain Admins
do NOT have problem, and a pre-existing user who already had local
profile on XP (for domain) does NOT have problem.

It seems to me that problem is on the server side (in AD) because if I put
one of the problem users into the Domain Admins group they can logon OK. If I
take them out of this group I get the error again.

On the server, I looked at the user rights "Access this computer from network",
"Allow logon locally" and "Deny logon locally". None of these seemed to have
any entries which would cause problem. Default Domain Controllers Policy is
where policy is generally set for my domain.

I've got auditing turned on (success and failure) for "audit account logon
events" and "audit logon events" and the security log does not show any
failures, just successful 672 & 673 events. I tried rebooting the DC.

I also looked at Local Security Policy on XP but didn't see anything. But a
part of me wonders if it's on the client (XP) side. I have recently been doing
some local profile migrating/renaming testing, but that doesn't seem like it
would've caused my problem. Especially since when I create a brand new user
and try to logon to XP for the very first time (no prior profile) I still get
error.
Hmm...

What could be causing this error? What should I focus on? (server or client)

Why is it only affecting new users or non-admin users?

Thanks for any help/ideas!

-Rich
 
C

Carey Frisch [MVP]

You receive the 'The local policy of this system does not permit you to logon interactively'?
http://www.jsifaq.com/SUBP/tip7500/rh7579.htm

--
Carey Frisch
Microsoft MVP
Windows XP - Shell/User
Microsoft Newsgroups

-------------------------------------------------------------------------------------------

:

| (I posted this also on the MS partner newsgroups but since this one is public
| I'm interested to see what peers might have to say...)
|
| Window XP Pro SP2 client connecting to Windows Server 2003 domain:
|
| All of a sudden, when trying to logon certain users from XP machine I now get
| "The local policy of this system does not permit you to logon interactively".
|
| But only certain users have problem. Users who are Domain Admins
| do NOT have problem, and a pre-existing user who already had local
| profile on XP (for domain) does NOT have problem.
|
| It seems to me that problem is on the server side (in AD) because if I put
| one of the problem users into the Domain Admins group they can logon OK. If I
| take them out of this group I get the error again.
|
| On the server, I looked at the user rights "Access this computer from network",
| "Allow logon locally" and "Deny logon locally". None of these seemed to have
| any entries which would cause problem. Default Domain Controllers Policy is
| where policy is generally set for my domain.
|
| I've got auditing turned on (success and failure) for "audit account logon
| events" and "audit logon events" and the security log does not show any
| failures, just successful 672 & 673 events. I tried rebooting the DC.
|
| I also looked at Local Security Policy on XP but didn't see anything. But a
| part of me wonders if it's on the client (XP) side. I have recently been doing
| some local profile migrating/renaming testing, but that doesn't seem like it
| would've caused my problem. Especially since when I create a brand new user
| and try to logon to XP for the very first time (no prior profile) I still get
| error.
| Hmm...
|
| What could be causing this error? What should I focus on? (server or client)
|
| Why is it only affecting new users or non-admin users?
|
| Thanks for any help/ideas!
|
| -Rich
 
J

John Tiesi

What you need to do is allow Domain Users to logon interactively in the
Domain Security Policy in the Administrative Tools. That fixes it.
 
R

Rich Roller

Yes, I found that I had to add both DomainUsers and Users to the policies "Logon
locally" and "Access this computer from network" and that seemed to make it
work.

But now I seem to have a larger issue of the XP machine's Local Computer Policy
being messed up and showing SID #'s instead of built-in group names... but that
should be the subject of another thread I guess.

-Rich
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top