Re: Loca Administrator "locked out"



Paul Adare ha scritto:

Sorry to contradict you here Mike, but this simply won't work. the Allow and Deny Logon locally policies are cumulative which means both the local settings and any domain based GPO settings are combined.

I noticed this behaviour, because I didn't get any positive results while adding a "random" user to that policy: Administrator STILL can't logon.

Your suggestion later in this thread about logging on with an account that is a member of Domain Admins should work, assuming that Domain Admins is still a member or the local Administrators group and that is indeed the account Administrator that has been denied the logon locally right and not the Administrators group.

I'm sorry, but as I believe to have mentioned before: the SAD thing is that no "Domain Admins" group is part of the local Administrators group.. :-/

I guess my only solution is to reinstall Win2k, or what do you think?

Regards,
OxygeN
.



Relevant Pages

  • Re: Confused
    ... Administrators group so they are administrators of the child domain, ... By default the Domain Admins of a domain are member of the ...
    (microsoft.public.win2000.active_directory)
  • Re: Deleteing C$ sharing
    ... to be local administrators. ... anything that will deny domain admins access to the computer. ... that auditing of logon events, policy change, and account management is ... administrators group on a domain computer as in [net localgroup ...
    (microsoft.public.win2000.security)
  • Re: Renamed local admin not enough rights
    ... aware of the fact that the SID for the admin account does not change. ... The Domain Admins are member of the local administrators group. ...
    (microsoft.public.win2000.active_directory)
  • Re: Loca Administrator "locked out"
    ... administrators to the logon locally user right in the GPO linked to the OU ... Admins is still a member or the local Administrators group and that is ... that no "Domain Admins" group is part of the local Administrators group.. ...
    (microsoft.public.win2000.security)
  • RE: software to control domain administrators
    ... "Does anyone know any software to control, audit, or restrict access or privileges to domain administrators." ... I will restate my mantra differently, If you can not trust someone to be in a position of complete un-adulterated control of your network, then they should not be in that position. ... >(assuming we are talking about NT/AD Domain Admins) ...
    (Security-Basics)