• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 3363
  • Last Modified:

Interactive Logon not Allowed windows 2003 ADS

Please read question carefully first !!!

1. I have a Domain Controller DC1 up and running
2. I created a user 'Aditya' in 'Manager' OU. (He is Member of Domain Users)
3. No GPO is applied on the OU Manager
4. One client PC1 is joined to domain.
5. I can normally logon to domain through PC1 using UID: Aditya (Physically sitting on the client PC1)
6. Now, I am on PC2 in the same network which is not joined to domain, Here I RDP to PC1 where I select UID: Aditya and enter password and Choose Domain DC1 (instead of 'PC1 this computer')
7. This time I can't logon it says "The local policy of this system does not permit you to logon interactively"
8. Then I changed such as Aditya = Member of Domain Administrators + Domain Users and then I can logon correctly using the same way described in step 6
9. I have also done these steps http://support.microsoft.com/default.aspx?scid=http://support.microsoft.com:80/support/kb/articles/Q247/9/89.ASP&NoWebContent=1#appliesto
and disabled Smartcard use for logon.
Where I am missing....
3 Solutions
it looks like you should configure pc1 remote access to allow domain user Aditya logon via remote desktop
properties of my computer - remote - select remote users
So you have a user ID that can log onto the workstation when sitting in front of the console, but not when attempting to RDP, correct?  Confirm that the user in question is a member of the Remote Desktop Users group on the PC or been granted equivalend rights, as discussed here: http://support.microsoft.com/kb/289289
check the following:
Aditya is added to users allowed to use remote desktop on the remote tab
add Aditya to the Local Group on PC1 Remote desktop users
Check the group policy object which linked to the OU where PC1 is resides on and add the account Aditya to the following items [ it's better to add remote desktop users group ]:
allow logon through terminal services.
allow logon locally.
Protect Your Employees from Wi-Fi Threats

As Wi-Fi growth and popularity continues to climb, not everyone understands the risks that come with connecting to public Wi-Fi or even offering Wi-Fi to employees, visitors and guests. Download the resource kit to make sure your safe wherever business takes you!

sunilcomputerAuthor Commented:
The user Aditya is a user on the domain DC1 not on PC1 and hence can't be added to RDP users on PC1 and there is also no group exists "Domain Users" on PC1. In your situation shall I need to add all of my hundreds of users to all the systems joined to domain.
Another thing while on the when domain I set Aditya = Domain Administrator it lets me log in perfectly through PC1 using RDP.

1. I have full Admin Rights on the Workstation PC1 and can easily RDP PC1(Local Machine) as well
2. I have a domain user Aditya which can logon to DC1 sitting physically on the workstation PC1
3. But when the user Aditya sits on another system PC2 (which is not joined to domain) he RDP to PC1 using following credentials:
Username: Aditya
Password: 141741x
Domain: DC1
then the message comes up.
if PC1 is a member of a domain, you CAN add domain userAditya  to local remote desktop users group.
Donald BarkerManager, Endpoint SecurityCommented:
You must on PC1 either add Aditya to the Remote desktop user group or the Local Administrator group.
sunilcomputerAuthor Commented:
I added Aditya to RDP Users on DC1
Then it started allowing Aditya to logon to DC1. Working scenario is following:
Aditya is sitting on PC2
He RDP to PC1 using Followinf Credentials:
Username: Aditya
Password: 141741x
Domain: DC1
Now another error message comes up that ......you are not allowed to logon to this session.
Another problem this way is once the user Aditya is a member of RDP Users on the domain he can directly RDP to DC1 without using PC1.

My Requirement is:
I need to logon Aditya on PC1 using his domain account (Physically sitting on PC1).
I need to logon Aditya on PC1 using his domain account (Physically sitting on PC2) where all the GPOs will be applied on the PC1\Aditya. (As I use do using VNC applications)
The user Aditya may be out of Network on a wan link. Aditya has the admin password of PC1
Router is properly configured & he can RDP to PC1 with no probs.
Aditya should never be able to RDP to DC1 directly he should only be able to logon to PC1.

you should add user Aditya  to the local remote desktop users group on PC1, not on the DC
sunilcomputerAuthor Commented:
Domain users are not listed in PC1 to be added in RDP Users.
start-control panel-administrative tools- computer management-local users and groups-groups-remote desktop users-add-advanced-find now.
you'll get the list of ALL users and groups available in the domain
you should be logged in to the pc1 with administrative rights to do that
sunilcomputerAuthor Commented:
I discovered It was a DNS Issue. Finally I added the user to RDP group in PC1 and it worked.
Thanks you all.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Improved Protection from Phishing Attacks

WatchGuard DNSWatch reduces malware infections by detecting and blocking malicious DNS requests, improving your ability to protect employees from phishing attacks. Learn more about our newest service included in Total Security Suite today!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now