local accounts do not have logon rights

From: Paul Berg (paul.berg@state.mn.us)
Date: 05/28/02


From: "Paul Berg" <paul.berg@state.mn.us>
Date: Tue, 28 May 2002 11:46:35 -0700


I just moved computers from one domain to another. Now,
when local user accounts, (local to the workstation), try
to logon, they get error messages that they are not
allowed interactive logons. I tried to remove the
computers from the domain and readd them and I get the
following error:
Unable to log on the Configuration Server's private user
account, which is required in order for the configuration
server to perform cloning and domain membership
operations. Logon failure: unknown user name or bad
password."
I have used NTRights as a workaround and that is working
fine for the short term. I look at the Local Security
Policy and all the local accounts have NO check in the
effective setting column. I look at the Domain Security
Policy and there is nothing listed under Logon Locally.
Anyone have any ideas???
Thanks!



Relevant Pages

  • Re: User Login
    ... filtering so that only this group gets the deny logon locally privilegs. ... the domain group called Domain Users is a member of the local ... put those user accounts into domain group and apply a GPO to the OU ... "Meinolf Weber" wrote: ...
    (microsoft.public.windows.server.active_directory)
  • Re: Account Lockout Policies
    ... Deleting user accounts after 30 days of inactivity allows a windows of opportunity of 30 days for an ex-user to re-use the network. ... If a technical solution is unavoidable due to a lack of management buy-in, there are a few ways that it can be achieved. ... Ascertain from those logs when users last logged in and add 30 days. ... From the users logon script, touch a unique file in a common area. ...
    (microsoft.public.security)
  • Re: Disabling Interactive Logon Against Security Group
    ... A less that fully perfect route to consider would be a logon script ... for those accounts that inquires as to what machine is being logged ... question "disable interactive logon privilages against specific OU/User ... If you set this in a GPO then the list that is to be denied that you ...
    (microsoft.public.security)
  • Re: Server 2003 Local Login
    ... No that's not possible, only domain accounts can be used for logon at DCs, ... the same behavior in Windows 2000 Server. ... >> Microsoft MVP - Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to generate a report of inactive domain user accounts
    ... It might be easier to key off of lastpasswordchange then last logon time, ... a report of inactive domain user accounts within an OU? ... SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers of ...
    (Focus-Microsoft)