Re: Loca Administrator "locked out"



Hi,

Put another user (do not put Administrator account or any group) into the
policy "Deny Logon Locally". This will override existing settings next time
the policy is refreshed. You can reboot the computer few times to speed up
the refresh process.

--
Mike
Microsoft MVP - Windows Security

"OxygeN" <bonnyREMOVEfused@xxxxxxxxxxxxxx> wrote in message
news:e5h4re$bd2$1@xxxxxxxxxxxxxxxx
OxygeN ha scritto:

It's not a "server" having this trouble, instead it is a client PC.
Now, I've created a "temp" OU and created a GP on it. In this GP, I've
set "Deny logon locally" to be *enabled* but also *empty*. At the end,
I've put the Computer account into that OU and rebooted it.

I've forgot to mention that NOTHING changed: I still can't log on with the
local administrator account. Is this because of the Local Policy being
applied *before* the Group Policy, and thus clearing the expected result?


.



Relevant Pages

  • Re: GPO errors in application eventlog
    ... The rename administrator account policy was not enabled. ... 1202 - SceCli "Security policies were propagated with warning. ... Check if the "Rename Administrator Account" security policy is enabled. ...
    (microsoft.public.windows.server.sbs)
  • RE: GPO errors in application eventlog
    ... these two events indicate that the group policy client-side ... These error messages can occur if the "Rename Administrator Account" ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: Account Rename Policy
    ... What the policies apply to depends on what policy was modified and what it was linked to as well as whether or not there is a competing policy. ... Don't get confuse i will explain clearly with some example.Thing i have TESTnamed DC and XYZ is a system is the member TEST domain. ... Iam applied Administrator Account rename group policy for all member systems in a TEST.COM Domain,it is renamed the adminstrator account only in member of domain systems,but now onlyits renaming the builtin global administrator account in the DC also. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Administrator cant login interactively
    ... remove the Administrator account from the Remote ... "The local policy of this system does not permit you to logon ... running Windows Small Business Server 2003 by using an Administrator account ... This is because members of the SBS Remote Operators group (of which Power ...
    (microsoft.public.windows.server.sbs)
  • RE: EVENT ID 1000 and 1202 events in Application Log afterimporting a security template
    ... EVENT ID 1000 and 1202 events in Application Log afterimporting a security template ... I have seen this issue when you rename administrator account, ... the policy to rename the Admin account both at the same time. ... which is true for most policy settings. ...
    (Focus-Microsoft)