Unable to unlock a Domain Controller as a member of a Domain Local group


i have run in strange problem windows server 2008 r2.

we have domain controller configured default policies. have normal user have created , made them member of domain local security group.

if edit default domain controllers policy (note don't this, test machine blowing away afterwards) allow domain local group log on locally permissions can log on normal user. if lock screen, cannot unlock screen , message 'logon failure: user has not been granted requested logon type @ computer'.

i can @ point click switch user , log on same user unlocks screen. difference can see unlock logon type 7, whereas switching user , logging on unlock interactive logon (type 2).

if change user member of domain global group , give log on locally permissions works fine.

any ideas?

thanks,

russ

hi thunder spook,

thanks post.

by default, members of users group have ability log on locally, administrator can deny right specific user or group accounts. explicitly denied right overrides allowed right. since works fine in domain global group , please check whether there's such limits in domain local security group.

in addition, far know, behavior can occur when user account not have user right  access computer network.

please see below similar question/solution .

http://answers.microsoft.com/en-us/windows/forum/windows_7-networking/logon-failure-the-user-has-not-been-granted-the/9cafeb92-ce7c-48d1-a286-f1202a5c8afb

best regards,

mary dong


please remember mark replies answers if , unmark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file