Re: domain user can't logon. help

From: leegold (nospam_at_mailandnews.com)
Date: 11/01/03


Date: Sat, 01 Nov 2003 14:17:10 GMT

Steven L Umbach wrote:

> Event ID 533 indicates that the computer that you are trying to log onto is not
> included in the list of domain computers the user is allowed to log onto as
> configured in the user account in Active Directory Users and Computers under
> account/log on to next to the logon hours tab or use net user username on the domain
> controller to see list of workstations user is allowed to logon to. An Event ID 534
> failure would indicate that the user does not have logon access based on effective
> settings in the computers Local Security Policy user rights. --- Steve

So, you're saying the problem is not local to the workstation,
but that I have make the adjustment on the domain controller ?
If so, I'll stop looking at the workstation and go to the server/
domain controller(?)

Thanks,
Lee

>
>
> "leegold" <leegold@mailandnews.com> wrote in message
> news:030c01c39ff1$e1165de0$a301280a@phx.gbl...
>
>>Win2k, sp4
>>
>>hi,
>>I can not log on to a particular computer with a particular
>>user/pw. On other computers I can log login with this
>>user/pw. So what I'm saying is there's a PC in a Domain
>>that gives the error info cited below when i try to login,
>>BUT only this PC has the problem - other ones gladly allow
>>this user to login. I have checked locally on the PC every
>>admin. setting i know of - I have done the obvious.
>>
>>This is stumping me, what about this PC's config. prevents
>>this user from loggin on? Other users on this "problem PC"
>>can logon (if i hadn't mentioned this). Below is the error
>>message and the log info. I've googled it and found no
>>fixes. Help.
>>Thanks, Lee G.
>>
>>
>>"Your account is configured to prevent you from using this
>>computer. Please try another computer."
>>
>>Event Type: Failure Audit
>>Event Source: Security
>>Event Category: Logon/Logoff
>>Event ID: 533
>>Date: 10/31/2003
>>Time: 3:43:07 PM
>>User: NT AUTHORITY\SYSTEM
>>Computer: XXX1100008487
>>Description:
>>Logon Failure:
>> Reason: User not allowed to logon at this computer
>> User Name: patronG0
>> Domain: LIBRARY
>> Logon Type: 2
>> Logon Process: User32
>> Authentication Package: Negotiate
>> Workstation Name: XXX1100008487
>>
>
>
>



Relevant Pages

  • RE: Unable to logon interactively.
    ... administrator user account to logon. ... You may check the default domain policy to confirm that the Log on Locally ... Start the Active Directory Users and Computers snap-in. ...
    (microsoft.public.windows.server.sbs)
  • Re: Login restriction
    ... And what options should I choose in GPO to be able to do what I want? ... logon on 12 different computers. ... these computers, access must be denied. ... then you can use the user account properties ...
    (microsoft.public.windows.server.active_directory)
  • Re: Login restriction
    ... Jorge Silva ... logon on 12 different computers. ... these computers, access must be denied. ... then you can use the user account properties ...
    (microsoft.public.windows.server.active_directory)
  • Re: Concurrent Logons
    ... their user account in Active Directory Users and Computers and you can use ... the user rights for logon locally and deny logon locally to control what ...
    (microsoft.public.windows.server.general)
  • How to stop all authenticated users from adding computers
    ... Currently anybody who has a user account can add computers to the domain. ... I've been reading that there is a default config that allows everyone to add ...
    (microsoft.public.windows.server.active_directory)