Re: allow non admin to logon to dc

From: Antonio Policelli (
Date: 05/28/03

Date: 28 May 2003 06:21:28 -0700

thanks matjaz!

it seems that active dir automagically placed all of domain
controllers in a OU called "domain controllers" if i give this user
log on locally in the gpo for this OU this will allow himn to log on
to all domain controllers.. i dont want that.. shuld i create a new
ou for only this domain controller and just mod that gpo? will this
create an active directory problem if i move the dc out to another

thanks AP

"Matjaz Ladava" <> wrote in message news:<OER#LOFJDHA.452@TK2MSFTNGP11.phx.gbl>...
> You need to grant him logon locally right in domain controllers GPO, but I
> would be very skeptic to allow users logging on to my DC. It is cheaper
> getting them separate workstation.
> Regards
> Matjaz Ladava
> "Antonio Policelli" <> wrote in message
> > in a remote office there is 2 servers. one is a win2k acitve
> > directory global catalog server. other is member server. one person
> > in that office needs to log on to the server but i don't want to make
> > them domain admin. all the remote offices are part of the big fat
> > domain -- there are no sub domains.
> >
> > the local user accounts and groups is disabled, cuz i guess its a
> > domain controller. how do i let this account log on there??
> >
> > thanks
> > AP

Relevant Pages

  • Re: Logon Using Terminal Services GPO
    ... Add a security filtering on the GPO, so it apply only to this DC. ... being admin of DC means admin of the Domain. ... domain controllers. ... So now they can logon remotely and administer the server (check event ...
  • Locked out of Server 2003!! Help!!!!
    ... Server 2003 at the backend. ... tried to apply to the Domain Controllers. ... Where the GPO has successfully ... it tells me that the user must be a member of the "Remote Desktop Users" ...
  • Re: 2008 DC 2003 GPO applied
    ... All DCs MUST be in the Domain controllers OU, do not move them out there. ... So move it back first and then i would restart the server. ... A GPO from 2003 configured should not be the problem normally. ...
  • RE: Win2K3 PDC not acting as time server
    ... You can try to set a GPO for Domain Controllers to use "AllSync" and point ... to a external time server. ... Then set a GPO on domain level to use NT5DS synchronization. ... > synchronize with an external time source. ...
  • Re: Benutzerberechtigung auf Domaincontroller
    ... Ich lege unter "Domain Controllers" eine weiter OU an und schiebe den betroffen DC da hinein. ... In der neuen OU erstelle ich ein GPO. ... Ist es richtig dass die Einstellungen der darüber liegenden GPOs die Einstellungen der darunterliegenden GPO überschreiben, sofoern diese auf "nicht definiert" stehen? ... Sich am Server anmelden, den Server neu starten, BackupExec verwalten ...