Not authorized to logon to Domain from this PC - error message

Not authorized to logon to Domain from this PC - error message

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Not authorized to logon to Domain from this PC - error message David H. Lipman 03-04-2008
Posted by David H. Lipman on March 4, 2008, 4:51 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
We are migrating some special, secured, PCs to a new Active Directory Domain.

A central IT technician was dispatched to lock down the PC and verify the PCs
Information
Assurance level.

In the process Domain Users get (not exact quote) "Not authorized to logon to
Domain from
this PC" as an error message when attempting a logon.

Only Domain Admins. can logon.

Any advice ?

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Roger Abell [MVP] on March 5, 2008, 9:19 am
If you were  Registered and logged in, you could reply and use other advanced thread options
In a machine's local security policy (or controlled by GPO but still
showing with gpedit) are user rights, including the user right to
Log on locally and a Deny logon locally.
Normally a domain joined machine has Users granted local logon,
and has Domain Users, Interactive, and Authenticated Users as
members of Users.
It sounds like something was broken in that linkage (good, as it
is needed to secure a machine from broad access) but was not
replaced with the needed.
For example, if domain\SpecialUsers need access, then that group
needs local login right either directly or more likely by being in
the machine's Users group which same is local logon.

Roger

> We are migrating some special, secured, PCs to a new Active Directory
> Domain.
>
> A central IT technician was dispatched to lock down the PC and verify the
> PCs Information
> Assurance level.
>
> In the process Domain Users get (not exact quote) "Not authorized to logon
> to Domain from
> this PC" as an error message when attempting a logon.
>
> Only Domain Admins. can logon.
>
> Any advice ?
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>



Posted by Kerry Brown on March 5, 2008, 9:35 am
If you were  Registered and logged in, you could reply and use other advanced thread options
How were the PCs locked down? Group policy? Look for the "Allow logon
locally" setting under

Computer configuration => Windows settings => Local policies => User rights
assignments

This would give a slightly different error message though so it may not be
the answer.

--
Kerry Brown
Microsoft MVP - Windows Desktop Experience
http://www.vistahelp.ca/phpBB2/



> We are migrating some special, secured, PCs to a new Active Directory
> Domain.
>
> A central IT technician was dispatched to lock down the PC and verify the
> PCs Information
> Assurance level.
>
> In the process Domain Users get (not exact quote) "Not authorized to logon
> to Domain from
> this PC" as an error message when attempting a logon.
>
> Only Domain Admins. can logon.
>
> Any advice ?
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>


Posted by David H. Lipman on March 5, 2008, 4:07 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| How were the PCs locked down? Group policy? Look for the "Allow logon
| locally" setting under
|
| Computer configuration => Windows settings => Local policies => User rights
| assignments
|
| This would give a slightly different error message though so it may not be
| the answer.
|

Thanx Kerry & Roger:

Apparently Registry settings were modified for local policies such that if the
Security Log
was full only an administrator could logon. They remotely pulled the security
Log but did
not change the settings to allow Domain Users to logon through the Domain.

By 3:40 pm, the issue was resolved. However I had to deal with cranky users
unable to
access that Domain from that PC.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Similar ThreadsPosted
Logon Message Error May 4, 2007, 4:50 pm
error message March 7, 2006, 9:29 pm
Error Message (???) July 1, 2006, 5:26 pm
error message February 23, 2007, 4:07 am
Error message instead of Homepage..... December 31, 2005, 6:31 am
may be getting security error message January 5, 2006, 3:06 pm
stop ie error message July 3, 2006, 11:38 pm
Update error message and firewall problems January 23, 2007, 5:30 pm
0x80072ee2 error message in Windows 2003 server August 10, 2005, 6:10 am
Having error message "Active Shield Missing Components" October 24, 2005, 9:27 pm

The site map in XML format XML site map

Contact Us | Privacy Policy