Link to home
Start Free TrialLog in
Avatar of charles_dilger
charles_dilgerFlag for United States of America

asked on

Domain Admin can't login to a vista computer if locked by a user, why?

In a Server 2003 Enviroment where all workstations have smart cards installed I've noticed I can't log into Vista computers if the user has the workstaion locked. In Win XP i see the "this workstaion in in use and has been locked..." message so i press Ctrl Alt Del and after entering my credentials it forces that user off and lets me log in. Vista however gives me the same message but i can't enter my credientials. It gives me a screen like the login one with boxes for the currently logged on user or smart card. No "other" box like the login screen does where I could enter admin credientials. How can I as admin get it so i can logonto a computer locked by a user without killing power and restarting?
Avatar of Casey Herman
Casey Herman
Flag of United States of America image

Has domain admins be added to local administrator's group?

Casey
Avatar of charles_dilger

ASKER

Yes and under xp I can log users out fine. This only seams to apply to Vista where i can't log them out.
so it is showing on the vista machine that it is there. OK  
Then have you tried disabling vista's advanced security features... you know the allow or deny crap.  It may be asking the empty session if it wants to allow the Administrator to log in and log the other session off.

Casey
you mean the UAC? No I havent tried urning that off yet. Its not asking for permission or anything in fact it says user xyz or an administrator can log into the computer but then desnt give me a place to enter a different username. I'll try killng the uac and see f that helps.
So describe the screen that you see again....  is it the "3 box" version for name, password, domain?   Or is it the "2 box" version for CertID, and PIN

Switching bewteen the two screens generally just takes another Crtl-Alt-Del or  a plull/insertion of the Smart Card
It's the "3 box" version. It first says the computer is in use and required you press CRTL Alt Del then i get two of the vista style logon buttons like for user accounts. One with the name domain\user (for the loged in user) and another that says insert smart card.
So, when you attempt to "take over" the currently running users session, are you using a Name/Password pair or a ID/PIN pair?
Just a username and password. Either mine, a member of the administrators group or as the domain admin. We don't use smart cards for logins just other stuff once logged in.
ASKER CERTIFIED SOLUTION
Avatar of charles_dilger
charles_dilger
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial