Solved

How can I allow a user to login to a server without making him a administrator?

Posted on 2008-10-06
14
200 Views
Last Modified: 2010-03-17
I need to be able to allow a user to login to the server. I know that I can make him a domain administrator but is there another way to do this?
0
Comment
Question by:microsymplex
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 4
  • 2
  • +1
14 Comments
 
LVL 6

Expert Comment

by:RemcovC
ID: 22650878
Grant him the allow log on locally right (security policies)
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 22650883

If it isn't a Domain Controller you just need to ensure the user (or the required group) has the "Log on Locally" right in the local security policy.

Chris
0
 

Author Comment

by:microsymplex
ID: 22650896
It is a domain controller......
0
NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

 
LVL 71

Expert Comment

by:Chris Dent
ID: 22650921

Then it would need to be done in the Default Domain Controller Policy. It's not something I'd recommend, DCs are very poor targets for user level access.

Chris
0
 

Author Comment

by:microsymplex
ID: 22650938
Yeah its actually for a tech that needs to do some testing without admin rights.  Where is the default domain controller policy?
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 22650974

Even user level access to a DC is a risk. But it's your system, so as long as you're happy with the risk :)

Linked to the Domain Controllers OU in Active Directory. If you have the Group Policy Management Console you should find it quite easily. Otherwise open the properties for the Domain Controllers OU in AD Users and Computers to access the Policy.

It's set under:

Computer Configuration / Windows Settings / Security Settings / Local Policies / User Rights Assignment

Then in "Allow Log on Locally".

Bear in mind that this policy effects all of your Domain Controllers.

Chris
0
 

Author Comment

by:microsymplex
ID: 22650978
Where do I find the local security settings on the server?
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 22651020

Start, Run, gpedit.msc.

Chris
0
 

Author Comment

by:microsymplex
ID: 22651042
duh... brain fart... ok but now allow logon locally is grayed out.
0
 
LVL 18

Expert Comment

by:sk_raja_raja
ID: 22651138
Why cant you make this user as a member of local admin of that server.....
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 22651161

Domain Controllers don't have local admin groups...

Chris
0
 
LVL 6

Expert Comment

by:RemcovC
ID: 22651218
domain controllers won't allow local policy change, you have to adjust de default domain policy

Go to Active Directory users and computers, find th OU in which your DC is, rightclick the OU and select properties.
Go to policy tab and edit the policy on this OU.
0
 
LVL 18

Expert Comment

by:sk_raja_raja
ID: 22651231
oops sorry chris..did not see microsymplex comment(It is a domain controller......)....:):):)
0
 
LVL 71

Accepted Solution

by:
Chris Dent earned 500 total points
ID: 22651259

> duh... brain fart... ok but now allow logon locally is grayed out.

Yeah, you need to be using the Default Domain Controllers Policy :) That's only where you find the local policy.

Chris
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

690 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question