Please Read: Significant Update Planned, Migrating Forum Software This Month

See more
See less

Denied Access to administrator account to logon locally

  • Filter
  • Time
  • Show
Clear All
new posts

  • Denied Access to administrator account to logon locally

    i was trying to deny acess to the users group in the domain controler security settings, and i guess i must of denied access to the administrators group as well, because you know how you get that msg, for average users when you first install win2k3 server
    "user cannot logon interactively" well i get that with the administrator accounts. Is there a way to fix this without re-formating? unfortunately i do not have remote access, or telnet access services enabled either

    thanks in advance

  • #2
    Can you logon in Directory Services Restore Mode using local Administrator account ?

    BTW, if the only restriction is logging on locally, you should have no problem to script the process of unlinking the GPO in qustion from Domain Controllers OU.

    The quick and dirty way to unlink all GPOs linked to Domain Controllers OU is:
    Set objContainer = GetObject _
      ("LDAP://ou=Domain Controllers,dc=domain,dc=com")
    objContainer.PutEx ADS_PROPERTY_CLEAR, "gPLink", 0
    objContainer.PutEx ADS_PROPERTY_CLEAR, "gPOptions", 0
    You can run the script remotely.
    Check out Technet's scriptcenter for more details.
    Guy Teverovsky
    "Smith & Wesson - the original point and click interface"


    • #3
      admin account cannot logon interactively via loca login

      Thanks Antid0t for your reply

      i can't logon to the server locally, as you can see, i'm new and i belive i have not set up OU's yet either, as i find that is important to do there a boot option on the windows 2003 server cd which allows me to restore active directory in it's default state?