Re: user group set not login in local, why administrator also not login ? how can i resolve it

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 07/22/05


Date: Thu, 21 Jul 2005 20:00:45 -0700

If you Deny local login to some group, like Users, then all accounts
in that group (directly or indirectly from nested groups) will not be
able to log in locally - and it does not matter who they are, what other
groups they are in, or whether those other groups are granted local
login right - deny will win.

-- 
Roger Abell
Microsoft MVP (Windows  Security)
"redsea" <redsea@xfnews.net.discuss> wrote in message
news:eoUOQzZjFHA.3288@TK2MSFTNGP09.phx.gbl...
> I dont think this result,how can i login in local?
>
> thanks a lot
>
>


Relevant Pages

  • Re: Administrator Cant Logon to Doamin Controller
    ... created a New User with Admin Rights and changed the Deny Locally Login ... Policy but removed administrator from one of the groups listed. ... > checked and changed the Deny local Login which did have Administrator ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Repost: Local logon and Network Access settings
    ... think require network login since they are over the wire do in fact ... In the default situation, Authenticated Users ... is a member of User on a member machine, and, Users are granted ... user accounts that should be allowed to log into the machines in SomeOU. ...
    (microsoft.public.windows.group_policy)
  • Re: Repost: Local logon and Network Access settings
    ... > think require network login since they are over the wire do in fact ... In the default situation, Authenticated Users ... > is a member of User on a member machine, and, Users are granted ... > user accounts that should be allowed to log into the machines in SomeOU. ...
    (microsoft.public.windows.group_policy)
  • AIX password enumeration possible
    ... BPR personnel can neither confirm or deny this behaviour exists in any OS other than AIX of versions mentioned below. ... In the case that the correct password is provided, the response is as follows: ... believed to be in the response from the login program after authentication ... Give accounts that have been restricted from remote logins strong passwords. ...
    (Bugtraq)
  • Re: Account Lockout Policies
    ... Allowing accounts to remain dormat for 30 days ... If a technical solution is unavoidable due to a lack of management buy-in, ... Extract login details from the security logs. ...
    (microsoft.public.security)