Article ID: 841188 - Last Review: December 3, 2007 - Revision: 4.3 "The local policy of this system does not permit you to logon interactively" error message when you try to log on to a computer that is running Windows Small Business Server 2003 by using an Administrator accountSYMPTOMSWhen you try to log on locally to a computer that is running
Microsoft Windows Small Business Server 2003 by using the built-in
Administrator account, or by using an account that is a member of the
Administrators group, you receive the following error message: The local policy of this system does not permit you to logon
interactively. When this issue occurs, an event that is similar to the following may appear in the security log in the Event Viewer: Event Type: Failure Audit CAUSEThis issue occurs if the user account that you use to log on
is a member of one or both of the following groups:
Because a Deny permission overrides an Allow permission, this policy setting prevents users from logging on to domain controllers in the domain, even if the "Allow log on locally" policy applies to those same users. Note Sometimes, the Administrator account may be a member of the Remote Operators group or the Domain Power Users group because of group nesting. For example, the Administrator account is a member of the Mobile Users group. Therefore, if you add the Mobile Users group as a member of the Remote Operators group, the Administrator account becomes a member of the Remote Operators group because of group nesting. RESOLUTIONTo resolve this issue, remove the Administrator account from the Remote
Operators group and the Domain Power Users group. You also must remove any group that contains the Administrator account from the Remote Operators group and the Domain Power Users group. You can make this change either by connecting to the Windows Small Business Server-based computer with a Remote Desktop connection or by installing the Microsoft Windows Server 2003 Administration Tools Pack (Adminpak.msi) on a Microsoft Windows XP Professional-based computer. For additional information about the Windows Server Administration Tools Pack, click the following article number to view the article in the Microsoft Knowledge Base: 304718
(http://support.microsoft.com/kb/304718/
)
Administering Windows Server-based computers using Windows XP Professional-based clients
To remove members from the Remote Operators group and the Domain Power Users group, follow these steps:
MORE INFORMATIONTo grant a user the right to make a Remote Desktop
connection to the Windows Small Business Server 2003-based computer to perform
administrative tasks, apply the Power Users Template to that user account. You
can apply this template when you create the user account or by running the
Change User Permissions Wizard. Important When you apply the Power Users Template to a user account, that user account is specifically denied access to log on to the Windows Small Business Server 2003-based computer from the local console. Therefore, do not apply this template to an Administrator account. For more information about how to apply templates to user accounts, see the "Manage users and groups" topic in Windows Small Business Server Help and Information. | Article Translations
|
Back to the top
