unable to login
Hi everyone, This is my first post. I installed Windows Server 2008 standard edition on a machine server01 and guided the installation to create an account "trivender" . Then I promoted the server as domain controller in the domain contoso.com.I logged in as trivender and removed trivender from the Administrators group.I logged off and tried to login again but I am getting an error "You cannot log on because the logon method you are using is not allowed on this computer.Please see your network administrator for more information." Please tell me how can I logon as user trivender ? Thanks trivender singh
July 31st, 2012 8:56am

What group is trivender in? can you log in as administrator? You are going to have to use the domain administrator account.
Free Windows Admin Tool Kit Click here and download it now
July 31st, 2012 9:25am

What group is trivender in? can you log in as administrator? You are going to have to use the domain administrator account.
July 31st, 2012 9:33am

trivender is now a member of Users and Domain Users groups. I am able to login with Administrator account. I want to know why I am not able to login as trivender
Free Windows Admin Tool Kit Click here and download it now
July 31st, 2012 10:07am

It is possible that since he is a member of the Users group, he is not allowed to log onto the server. I believe that is a setting in the security policy or group policy.
July 31st, 2012 10:08am

trivender is now a member of Users and Domain Users groups. I am able to login with Administrator account. I want to know why I am not able to login as trivender
Free Windows Admin Tool Kit Click here and download it now
July 31st, 2012 10:14am

It is possible that since he is a member of the Users group, he is not allowed to log onto the server. I believe that is a setting in the security policy or group policy.
July 31st, 2012 10:16am

trivender is now a member of Users and Domain Users groups. I am able to login with Administrator account. I want to know why I am not able to login as trivender Members of Domain Users or Users cannot log on to Domain Controllers ! The Default Domain Controller policy prevents "users" logging on to the domain controllers. By default, users belonging to following groups (highlighted in screenshot below) can log on to Domain controllers 2003, 2008/R2 DDP includes Domain Admins and Enterprise Admins groups as well On 2012 AD, Domain Admins and Enterprise Admins are part of Domain\Administrators group If you would like to log on to the domain controllers using your id 'trivender', then follow the steps given in article below Permit users to log on locally to a domain controller http://technet.microsoft.com/en-us/library/cc785165(v=ws.10).aspx OR Add your id 'trivender' to any of the groups mentioned in screen shot above. Also, to add your id to any of the groups, you need to log on to domain controller as administrator. HTH I do not represent the organisation I work for, all the opinions expressed here are my own. This posting is provided "AS IS" with no warranties or guarantees and confers no rights. - .... .- -. -.- ... --..-- ... .- -. - --- ... ....
Free Windows Admin Tool Kit Click here and download it now
July 31st, 2012 10:55am

Hi, Since you have promoted the Windows Server 2008 machine as a DC in the domain, and you have removed the user from the Administrators group, the user have no permission to logon to the machine at this time. Please understand that, by default, only members belong to the following groups could logon a DC, these groups are: Account Operators, Administrators, Backup Operators, Print Operators, and Server Operators. So if you want the user could logon to the DC, we could configure the security setting to permit the common user log on locally to the DC. For details, please refer to the article below. Allow log on locally http://technet.microsoft.com/en-us/library/cc756809(v=ws.10).aspx Regards, Andy
August 1st, 2012 4:57am

Hi all, I have a small question, If a new server 2008 is setup and i create around 300 user account, you mean to say, no user will be allowed to login unless ALL THE USERS are added to the Default Domain Controller Security Settings-Allow log on locally.. furter..we can edit or add the user in server 2003, wherein in 2008 that seems to be locked and could not add users or groups
Free Windows Admin Tool Kit Click here and download it now
September 5th, 2012 7:07am

Hi all, I have a small question, If a new server 2008 is setup and i create around 300 user account, you mean to say, no user will be allowed to login unless ALL THE USERS are added to the Default Domain Controller Security Settings-Allow log on locally.. furter..we can edit or add the user in server 2003, wherein in 2008 that seems to be locked and could not add users or groups
September 5th, 2012 7:09am

Madhavan, It's not a good practice to allow Users to log on to domain controllers ! Technically it's possible however, It's an security issue. You may/can allow users to log on remotely to member servers though. In this case, you need to add desired users to "Log on through remote desktop or terminal services" policy settings. Hope that helps I do not represent the organisation I work for, all the opinions expressed here are my own. This posting is provided "AS IS" with no warranties or guarantees and confers no rights. - .... .- -. -.- ... --..-- ... .- -. - --- ... ....
Free Windows Admin Tool Kit Click here and download it now
September 5th, 2012 7:17am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics