Solved

local rule locks admin out! after reboot my w2k server declines any login by local or domain admin. is there any chance to login again?

Posted on 2004-03-23
6
143 Views
Last Modified: 2010-04-13
I have a 2 server system running. Maschine A is the DC and Maschine B will be used just as Fileserver. During setup everything was configured as a workgroup and later on I set up the DC and moved Maschien B onto the Domain. On Both Maschines the Terminal Services were installed and running. After Reboot of Maschine A all worked fine but Maschine B came up with a message that the terminal service licenz service could not start up. I didn´t mind that error as I was expecting to fix it later on but today I had to restart both maschines as new dirvers were installed and now Maschine B declines all login request by any admin (local or domain) the message tells me interactive login forbitten by local security settings. Is there any workaround so I could login with admin rights and try to fix the local login settings?
0
Comment
Question by:fm44
  • 3
  • 2
6 Comments
 
LVL 3

Expert Comment

by:infradawn
ID: 10657001
If B is still a member of the domain configure Group Policy (on the DC) to overide any local policy so that defined users (administators) are granted interactive logon on B.


iD
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 10657399
Try booting up machine "B" with "Last Known Good Config" if you haven't logged in since the problem occured. Worth a try.
0
 

Author Comment

by:fm44
ID: 10685795
I will try but actually I can´t log in with der domain admin either
0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 
LVL 3

Expert Comment

by:infradawn
ID: 10702800
Do you mean that you can't logon to the DC either?

iD
0
 

Author Comment

by:fm44
ID: 10703105
No, sorry if I gave you the wrong impression. I can´t login on maschine "B" using the domain admin account.
0
 
LVL 3

Accepted Solution

by:
infradawn earned 500 total points
ID: 10712757
Ok, so you need to logon to machine 'A' (the DC) with your Domain Admins account and configure Group Policy (Restricted Groups) so that when that policy is applied to machine 'B' (every 90 minutes by default or after a re-boot) the local\administrators group on machine 'B' has the Domains Admin group as a member. Then you'll be able to logon to machine 'B' with any Domain Admins account.


iD
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
There are many Password Managers (PM) out there to choose from. PM's can help with your password habits and routines, but they should not be a crutch you rely on too heavily. I also have an article for company/enterprise PM's.
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now