Re: Loca Administrator "locked out"



Hi,

Since this server is part of domain create new OU (e.g. Temp OU) and create
new policy on this OU that will override local policy (e.g. make sure that
in this policy local administrator is _not_ part of "Deny logon locally").
Move the computer account to this Temp OU and reboot Windows 2000 server and
wait for it to refresh the policy.

--
Mike
Microsoft MVP - Windows Security

"OxygeN" <bonnyREMOVEfused@xxxxxxxxxxxxxx> wrote in message
news:e5gv74$8mv$1@xxxxxxxxxxxxxxxx
Hello all.
I got a "nice" problem here: one of my Win2k (SP4) PCs has the local
Administrator account "locked out" by means of the PCs local policies (the
parameter "Deny logon locally" has been set with "Administrator").
Now, the sad part of this all is the fact that *no other* account is
member of "Administrators" local group.
So, I can't "administer" that PC anymore.
The PC is a domain member (Win2k domain), so maybe there's some "trick" or
"workaround" to fix this situation?

Many thanks in advance.


.



Relevant Pages

  • Re: administrator locked out of SBS 2003
    ... Try to logon to the console using this account. ... see which groups the administrator is a member of and post back ... Even the VMware KB's as I've all ready discovered the server V2.0 ... so I deleted the policy. ...
    (microsoft.public.windows.server.sbs)
  • Re: GP loopback processing on Windows 2003 terminal service, strange problem!
    ... You should not have to go through all that to get the policy to work ... Check that your other W2003 Server points ONLY to the domain controller ... > any other GP's then logging on to the TS server. ... > is not local administrator on this TS server? ...
    (microsoft.public.windows.group_policy)
  • Re: windows 20000 problem
    ... So you are saying the problem is on just this one particular server that is ... in an OU with other servers that do not lock down the domain admin account. ... The part about logging in as local account that bypasses this policy ... > and the administrator is in an OU where the policy doesnt apply. ...
    (microsoft.public.win2000.security)
  • Re: administrator locked out of SBS 2003
    ... enterprise admins ... group policy creator owners ... Other than lacking exchange administrator this is pretty much normal. ... Even the VMware KB's as I've all ready discovered the server V2.0 ...
    (microsoft.public.windows.server.sbs)
  • Re: GP loopback processing on Windows 2003 terminal service, strange problem!
    ... environment debug logging at the verbose level, reboot the server and log on ... as the administrator, ... > You should not have to go through all that to get the policy to work ...
    (microsoft.public.windows.group_policy)