Security policy problems with new users.

Posted on 2004-11-03
Last Modified: 2010-04-19
All new users created on my windows 2003 ent have the same problem, when they try to logon on any workstation they get the error "no interactive sessions allowed by local security policy" (or something like that. Sorry my system is on a different language). I have checked the security policy of the domain and the domain controller and they seem to be ok. Old users are working with no problems.
Question by:DPRIETO
    LVL 25

    Expert Comment

    as the error says,,, the problem is with the local security policy and not the domain security... so what you need to do is go to the client and open up the local/group security policy MMC and look for the following:

    local computer policy>computer config>windows settings>security Settings>local policy> user rights>

    from there you need to look for the log on locally right and make sure that new users are a member of a group that is actually allowed to log on to the workstations....

    off the top of my head im thinking that possibly your new users aren't even in the "domain users" group for some reason

    Author Comment

    New users are members of "domain users" as old ones. Old users can logon on any workstation but the new ones can't the error is "local policy does not allow you to login interactively". We select the proper domain on the domain list box. A have tried to include them, just for testing, on adminitrators group and it made no differences.
    LVL 25

    Accepted Solution

    well did you look at the MMC as i suggested?  check to see which groups are allowed to log on.... also try explicidly adding one of the new users to the log on locally right and see if that makes a difference...  also check the deny log on locally list

    Author Comment

    I have restarted the server last night and now every thing is working....... I hate this things.... Anyway, thanks for your help

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    It is a known fact that servers reach the end of their lives. Some get there quicker than others, based on age, manufacturer, usage and several other factors. However, if your organization has spent time deploying Microsoft's Active Directory server…
    Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
    To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
    This video discusses moving either the default database or any database to a new volume.

    779 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    11 Experts available now in Live!

    Get 1:1 Help Now