Quantcast
Results 1 to 7 of 7

Logon Problem

  1. #1
    Jadames is offline Junior Member
    Enjoys Windows 7 Forums
     
    Join Date
    Oct 2010
    Posts
    25

    Logon Problem

    Hi, I have windows server 2008 r2 foundation as active directory domain controller and 5 client mashines running xp pro. when I try to log on to the domain from any of the client I get the message "The local policy of this system does not permit you to logon interactively" any ideas how to resolve this problem? thanks

    Reply With Quote Reply With Quote

  2. #2
    Trouble's Avatar
    Trouble is offline Administrator
    Noob Whisperer
     
    Join Date
    Nov 2009
    Posts
    5,922
    Blog Entries
    2

    Re: Logon Problem

    That particular error is controlled by a local security policy setting. It is affected by both the Allow log on locally and the Deny log on locally setting.
    So, log on to the local machine with a local administrator account (not domain admin or user, local admin only) and type
    secpol.msc into the search or run dialog box and hit enter
    In the left column
    Expand Local Policies
    Select User Rigts Assignment and examine who is listed for both of those policies.
    You should see users and administrators groups included in allowed and they should not be present in deny (usually only guests).
    Check each indivdual client machine for these settings.
    If they appear to be correct and you are certain that no user is included in any group that is listed in the Deny log on locally then;
    Take one of the client machines and unjoin it from the domain, join it back to a work group (anyname, workgroup is fine) then,
    Check the server and make sure you remove the machine account for that computer from the Active Directory database.
    Reboot the client computer, log on as a local administrator and rejoin the domain, reboot again and try to logon with domain credentials, start with domain admin account just to make sure.
    Last edited by Trouble; 05-31-2011 at 12:15 PM.
    Yesterday was, Today is, but ahh Tomorrow...mystery, suspense and a promise of hope.


    Reply With Quote Reply With Quote

  3. #3
    Jadames is offline Junior Member Thread Starter Thread Starter
    Enjoys Windows 7 Forums
     
    Join Date
    Oct 2010
    Posts
    25

    Re: Logon Problem

    Quote Originally Posted by Trouble View Post
    That particular error is controlled by a local security policy setting. It is affected by both the Allow log on locally and the Deny log on locally setting.
    So, log on to the local machine with a local administrator account (not domain admin or user, local admin only) and type
    secpol.msc into the search or run dialog box and hit enter
    In the left column
    Expand Local Policies
    Select User Rigts Assignment and examine who is listed for both of those policies.
    You should see users and administrators groups included in allowed and they should not be present in deny (usually only guests).
    Check each indivdual client machine for these settings.
    If they appear to be correct and you are certain that no user is included in any group that is listed in the Deny log on locally then;
    Take one of the client machines and unjoin it from the domain, join it back to a work group (anyname, workgroup is fine) then,
    Check the server and make sure you remove the machine account for that computer from the Active Directory database.
    Reboot the client computer, log on as a local administrator and rejoin the domain, reboot again and try to logon with domain credentials, start with domain admin account just to make sure.
    I checked those two policies and deny logon has guest and logon locally only administrators i tried to add users but the option for adding users or groups is greyed out even logging in as an administrator

    Reply With Quote Reply With Quote

  4. #4
    Trouble's Avatar
    Trouble is offline Administrator
    Noob Whisperer
     
    Join Date
    Nov 2009
    Posts
    5,922
    Blog Entries
    2

    Re: Logon Problem

    That would suggest that the actual local policy is being impacted by a persistent Domain Policy. If you try unjoining the machine from the domain as I suggested earlier are you able to effectively change the settings to include users?
    Additionally adding the domain users group to the local administrators group on the client machine might help. Can you log on to the local machine using the domain administrator's credentials (domain admins are automatically added to the local admins group I believe)?
    Have you added or changed any OUs or GPOs recently or are you aware of any MS security updates to the server that may have affected (like did you recently install service Pack 1 for 2k8r2 server).
    Yesterday was, Today is, but ahh Tomorrow...mystery, suspense and a promise of hope.


    Reply With Quote Reply With Quote

  5. #5
    Jadames is offline Junior Member Thread Starter Thread Starter
    Enjoys Windows 7 Forums
     
    Join Date
    Oct 2010
    Posts
    25

    Re: Logon Problem

    Quote Originally Posted by Trouble View Post
    That would suggest that the actual local policy is being impacted by a persistent Domain Policy. If you try unjoining the machine from the domain as I suggested earlier are you able to effectively change the settings to include users?
    Additionally adding the domain users group to the local administrators group on the client machine might help. Can you log on to the local machine using the domain administrator's credentials (domain admins are automatically added to the local admins group I believe)?
    Have you added or changed any OUs or GPOs recently or are you aware of any MS security updates to the server that may have affected (like did you recently install service Pack 1 for 2k8r2 server).
    Definetly is a domain policy overiding the local policy it let me change the settings when out of the domain. What should I look for on the domain policy. It only has the default domain policy and the default domain controller policy.

    Reply With Quote Reply With Quote

  6. #6
    Trouble's Avatar
    Trouble is offline Administrator
    Noob Whisperer
     
    Join Date
    Nov 2009
    Posts
    5,922
    Blog Entries
    2

    Re: Logon Problem

    Sorry I don't have my 2k8 r2 server up and running right now so I can't help with specifics except to say that you will probably need to take a look at RSoP for the specific container that includes your users and or computers that are having problems logging on. This may help some if you're not familiar with the Resulatant Set of Policies Snap-In.
    Remember domain policies can affect both users, groups, computers, and OUs, so double check for any conflicting group memberships.
    You still haven't said whether or not you can logon to the problem client machines using the domain administrator's account. Yes or No?
    This will help determine if it's a user/group issue or a computer/machine issue.
    Yesterday was, Today is, but ahh Tomorrow...mystery, suspense and a promise of hope.


    Reply With Quote Reply With Quote

  7. #7
    Jadames is offline Junior Member Thread Starter Thread Starter
    Enjoys Windows 7 Forums
     
    Join Date
    Oct 2010
    Posts
    25

    Wink Re: Logon Problem

    I added domain users and administrators to the allow logon locally and allow log on throu remote desktop services
    on both domain policy and domain controller policy and now I can log on any client computer to the domain thanks Randy once again for pointing me in the right direction.
    Attached Thumbnails Attached Thumbnails Click image for larger version. 

Name:	Untitled2.png 
Views:	140 
Size:	115.3 KB 
ID:	13824   Click image for larger version. 

Name:	Untitled.png 
Views:	175 
Size:	116.1 KB 
ID:	13823  

    Reply With Quote Reply With Quote

Similar Threads

  1. Replies: 1
    Last Post: 12-22-2010, 10:11 AM
  2. How To Display Domain and Local Logon Accounts on Logon Screen
    By brianafischer in forum Windows 7 Graphics
    Replies: 10
    Last Post: 12-02-2010, 04:31 PM
  3. Custom "Windows logon sound" doesn't play on initial logon
    By mourning due in forum Windows 7 Support
    Replies: 7
    Last Post: 12-28-2009, 08:39 PM
  4. Domain Logon over DUN/VPN
    By mkhan01 in forum Windows 7 Networking
    Replies: 1
    Last Post: 11-16-2009, 08:25 PM
  5. logon problem
    By nicook5 in forum Windows Vista Support
    Replies: 2
    Last Post: 08-26-2007, 11:20 AM

Visitors found this page by searching for:

add user to allow log on locally grayed out windows 7

rsop grayed out windows 7

allow logon locally greyed out 2008

allow logon locally greyed out server 2008

allow logon locally greyed out windows 7

add users allow log on locally greyed out server 2008

allow logon locally windows 7

default values deny logon locally greyed out windows 7

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •