Solved

The local policy of this system does not permit you to logon interactively

Posted on 2003-12-01
8
117,899 Views
Last Modified: 2013-12-04
I recently upgraded our second server to be an additional Active Directory computer.  When I did this all of the user that were in the group Domain Users would get the error message "The local policy of this system does not permit you to logon interactively" when they tried to log into the server through Terminal Services.  I know that I could add them to the administrator group and they wouldn't get this message, but I don't want to have to do this.

I have gone into gpedit.msc and for the policy Log On Locally, I have added the group "Domain Users" however, the Effective Settings, has this policy disabled for Domain Users.  Where is this effective setting coming from?

Thanks

0
Comment
Question by:dovcamp
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
8 Comments
 
LVL 32

Accepted Solution

by:
LucF earned 500 total points
ID: 9851897
0
 
LVL 32

Expert Comment

by:LucF
ID: 9852599
Glad to help you solve your problem.
0
IoT Devices - Fast, Cheap or Secure…Pick Two

The IoT market is growing at a rapid pace and manufacturers are under pressure to quickly provide new products. Can you be sure that your devices do what they're supposed to do, while still being secure?

 

Expert Comment

by:JamesYong
ID: 11672284
I changed my Group Policy. Now I cannot even logon into my Domain using the correct user name and password.
I got the following message after I type in administrator as user name . And I use the correct password:

"Local Policy of this system does not permit you to logon interactively"

Is there any way to logon to the Domain and change the Group Policy?

Or do I you to re-install the windows 2000 server starting from scratch?
0
 

Expert Comment

by:crarey
ID: 13472916
I have three servers that are load balanced. i just added the third server, and I receive the error "Local Policy of this system does not permit you to logon interactively". A domain user can login to the first two servers, but not on the third.

I tried the one the fix above, but a domain user is still unable to login to the third server.

Any ideas?
0
 

Expert Comment

by:LostinParadise
ID: 15083017
I too have the problem, but it is occurring in SBS 2003. I have tried the above solutioni and can get at the way to were it wants me to execute a secedit command.  The syntax they are asking for does not exist.  Any idea's  Can I get away with a simple reboot?
0
 

Expert Comment

by:alan_8sg
ID: 20442193
User May Be Authenticated by Wrong Domain
View products that this article applies to.
Article ID : 227904
Last Review : February 26, 2007
Revision : 3.2
This article was previously published under Q227904
SYMPTOMS
When you log on to a Windows 2000 domain, you may receive either or both of the following error messages: " Logon Denied--The password is incorrect. Please retype your password. Letters in passwords must be typed using the correct case. Make sure that Caps Lock key is not accidentally on.
The Local policy of this system does not permit you to log on interactively.

Back to the top

CAUSE
This behavior can occur if two domain controllers are promoted using Dcpromo.exe with identical domain names, and both domain controllers are installed as the first domain controller for the specified domain.

You cannot reliably configure two separate domains with the same name. Because both domains register with DNS, there is no way to control which name is resolved to the client.
Back to the top

RESOLUTION
Two resolve this issue, use either of the following methods: " Remove one of the domains with the identical name.
" Using Dcpromo.exe, demote all the domain controllers in the second domain, then use Dcpromo.exe to promote these computers to be domain controllers in the original domain.
0

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In today's information driven age, entrepreneurs have so many great tools and options at their disposal to help turn good ideas into a thriving business. With cloud-based online services, such as Amazon's Web Services (AWS) or Microsoft's Azure, bus…
This is a guide to the following problem (not exclusive but here) on Windows: Users need our support and we supporters often use global administrative accounts to do this. Using these accounts safely is a real challenge. Any admin who takes se…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
Suggested Courses

615 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question