Matching account name in local SAM and Domain - default to domain
I have users accounts with the same name in the local SAM of a 2008 R2 server and in the domain that the server is a member of.
While typing the user name into the User Name field, the "Log on to:" field shows my domain name until I get to the last letter of the User Name. At that point, it has seemingly found the match with the local account and changes the Log On
to: to the computername (Local SAM) instead of leaving it at the domain.
Can anyone point me to something that explains how to control this behavior? Specifically, I would like it to not change to the local computer even when it finds a match.
Thanks!
Andy
June 7th, 2010 9:35pm
Hello,
starting with Windows server 2008 you have to use the following ways to logon to the domain:
domain\username or username@domain.com
If you choose only the username without specifying the domain you logon locally if the same username exists.Best regards Meinolf Weber Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
June 8th, 2010 12:13am
Thank you Meinolf.
No override to this that you know of to make it ignore the local account and default to domain?
June 9th, 2010 3:51pm
Hello,
maybe this GPO prevents you to logon locally first:
Computer configuration, Administrative templates, System, Logon, in the right pane "Assign a default domain for logon"Best regards Meinolf Weber Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
June 9th, 2010 4:01pm
Thank You for the suggestion. I did try to change that but it didn't seem to make a difference.
Based on the description, I didn't really think it would - seems like it's more to set a default domain of one other than the one which the computer is a member of.
Do you have a suggestion for any Microsoft KB's / technet articles that talk about this change in 2008?
June 9th, 2010 6:02pm
Hello,
this will also work with your own domain name, i tested this on Windows Vista/Windows server 2008 member servers and not longer had to specify the domain name before the username.
I don't have any document about this changes that only
user@domain.com (UserPrincipalName logon) or domain\user (down-level logon name) can be used.Best regards Meinolf Weber Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
June 10th, 2010 1:42pm
I do agree that this works w/ local domain to a point.
It shows the domain name on the screen until I type the last letter of a local account and at that point it switches to the local computer name.
Thanks for your helpful thoughts!
Andy
June 11th, 2010 12:00am
Hello,
you're welcome. Glad to help. :-)Best regards Meinolf Weber Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
June 11th, 2010 12:25am