SBS 2011 Local policy does not allow you to log in interactively AT A CLIENT MACHINE

I am helping a friend on vacation. His boss called saying a new user on their SBS 2011 box can't log into their desktop - they get the 'local policy does not allow you to log on interactively'.

This is a standard domain user logging in at a DESKTOP - I know only domain admins can get onto the SBS box directly,

Looking at local policy, I see the entry log in locally has 1 user that always sits at that desk, local admins and domain admins.  The add button and that screen is grey - can't add / change anything.

I wound up going into control userpasswords2 and making this user a local admin and she could get in.  

How would I put comain users in the log in local screen since it's greyed out (that was local policy on that machine - and she couldn't log in on other machines either so it's likely something someone did at each machine? (to lock it to 1 user and local and domain admins).

usually domain users would be in the 'log in locally' policy for a desktop, right?

I forget - does domain group policy override local policy or vice versa?
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

mcsweenSr. Network AdministratorCommented:
This is probably set at a domain level group policy.  Also; check the "deny log in locally" policy setting.
James HIT DirectorCommented:
I have seen servers do this but not desktops.
Here is the way to fix this.

goto ---> Run--->gpedit.msc--->
computerconfiguration-->computerconfiguration-->windows settings-->localpolicies-->user rights assignment-->allow userlogon locally-->Adduser Name

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
BeGentleWithMe-INeedHelpAuthor Commented:
spartan - that's for the local machine, right? Have to go to each one? can't do it at dimain level?

looking in active directory, I saw all the computers under the user folder.  then in group policy, there's no GPs for that folder (but I guess I have to look above that to see what folders that users folder is in and if they have GPOs attached, right?
mcsweenSr. Network AdministratorCommented:
Yes, look to see if there is a GPO linked at the domain level.  Someone may have modified the Default Domain Policy as well though this is against MS Best Practices.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.