Windows 2000 Advanced Server logon error

Hi Guys,

We have a system running Windows 2000 Advanced Server, SP4, clean installation. Active Directory has just been installed, a new user (Tom) has been added in 'Active Directory Users and Computers'.

When we try and logon as Tom to the server locally the following error occurs:  The local policy of the system does not permit you to logon interactively.  Logging on as Administrator is OK.

Have tried going into local security settings and double clicked on the setting 'log on locally' and added the new user (Tom) to the list, restarted the computer and still can't logon as 'Tom'.  Also tried to create a second new user, and adding to the 'log on locally' setting, same error.

Then logged on as Administrator, went to Local Security Settings and double clicked on 'log on locally' setting.  In the Local Security Policy setting the Local Policy Setting is ticked but the effective policy is unticked and cannot be ticked as it is ghosted out.

In the Local Security Settings dialogue box it states if Domain-Level Policy Settings are defined they override local policy settings.  Cannot see anything in Domain Level Policy settings that would override local policy settings.

Your help is much appreciated. New to Win2000 Advanced Server, so take it slow.


Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Hi Chiarne,

edit the default domain controllers security policy - why do you want users logging on the your DC anyway - this is bad news, you will fill it up with random profiles which is a bad idea....  


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
ChiarneAuthor Commented:
Hi Jay_Jay70,

Thanks, problem solved.  Was using this system as a test, wouldn't do this in a real time situation.

Appreciate your help.


no worries :)
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows 2000

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.