Windows 2008 DC - Cannot login with a newly created admin account other than 'administrator'
I have created several new admin accounts (e.g. besadmin), and have granted "log on locally" but cannot log onto this server with it. I can, however, log into another Win2003 server locally with the same account. When I login with besadmin, I receive the following message: "The User Profile Service service failed the logon. User profile cannot be loaded."
December 24th, 2010 10:03am

For 2008 Domain controller, you need to configure the security setting in Default Domain Controller Policy GPO: 1. On the Windows Server 2008 domain controller, click Start, type gpmc.msc in the Start Search box, and press Enter to open the Group Policy Management console. 2. In the Group Policy Management console, expand \Domain Controllers, right-click Default Domain Controller Policy, and click Edit. 3. In the Group Policy Management Editor window, expand Computer Configuration\Windows Settings\Security Settings\Local Policies\User Right Assignment, and then you will see the security setting Allow log on locally in the right pane. 4. Double-click the security setting Allow log on locally, click Add User or Group tab, click Browse, type domain users in the box, click Check Names, and click OK three times to apply the settings. 5. On the Windows Server 2008 domain controller, run command gpupdate /force to apply the policy. Joy, Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
December 24th, 2010 11:12am

Hello, an administrative account like domain admin or enterprise admin can logon to each domain machine without any additional configuration, so i can not really see the problem. Which security groups are they member of? Additional see: http://support.microsoft.com/kb/947215 Best regards Meinolf Weber Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
December 24th, 2010 5:29pm

Hi, Thanks for posting here. Are there any error or warning that relate with this issue recorded in event log, could you post the Event ID and description here for further investigation? Have you deployed any antivirus software on this domain controller? If yes, please temporarily disable it, restart and logon again. · Please try granting one of new create account full Control permissions on C:\users Folder and Replace. · Regedit and changed the value with the information below: Path "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList" Created the following values below: - Default REG_EXPAND_SZ %SystemDrive%\Users\Default - ProfilesDirectory REG_EXPAND_SZ %SystemDrive%\Users - ProgramData REG_EXPAND_SZ %SystemDrive%\ProgramData - Public REG_EXPAND_SZ %SystemDrive%\Users\Public Thanks. Tiger LiPlease remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
December 27th, 2010 12:13am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics