Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Wanet Telecoms Ltd on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Local Policy SNAFU

Status
Not open for further replies.

imquazar

MIS
Sep 23, 2003
54
US
You'll love this.

Saturday I built up a server, complete with fileshare permissions, VPN access, and the whole nine yards (XP PRO with SP2 by the way, and I know about the limited functionality of VPN on XP, but hey, it does what we need it to do) so after getting it all put together, I wanted to lockdown the server's ability to allow someone to login locally from the keyboard sitting in front of the server. Not a difficult task unless you get distracted which is what happened to me.

So, editing the group policies using GPEDIT, I'm under Computer Configuration/Windows Settings/Security Settings/Local Policies/User Rights Assignment.

Here we see two fields. Deny Logon locally and Logon Locally.

Simple enough so far... and this is a very small scenario in which all of the users are in the users group with the exception of three accounts for administration which are in the administrator's group.

So then - Deny logon locally, I wound up selecting the Users group, and logon locally, I removed the users group.

WRONG - Now NOBODY can logon locally.. not even the adminstrator accounts. I can get in to the VPN but it's only got limited access to only what's needed (for obvious reasons) and I can bring up the repair console with the adminstrator login, other than that I'm dead in the water.

Any ideas on how I can get this undone, or reset back to the defaults?

Thanks,
-IQ
 
The NTRights utility would have been the way to go, but the other day I was thinking about the other options and I decided to open 3389 on the router and try RDP and it worked! I was able to go right in and edit the policy and life is good.

I was also able to locate the NTRights util on the server 2003 resource kit.

Thanks for the response !!
-IQ
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top