Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Only admin can log in

Status
Not open for further replies.

Jiff

MIS
Apr 4, 2001
20
GB
Got a windows 2000 small domain an this is driving me nuts!
I've created several user accounts, but none of them can log in! You can log in fine as administrator from any of the workstations, but when users log in, they're asked to change their password - then get told they do not have permission to change the password! If I do not allow the password to be changed, it reports that the domain controller was not available and cannot log you on!
I created myself an account with admin rights and can log in okay - but then I don't have admin rights! What on earth is going on???
 
This may sound really elementary, but see what you have checked on the user properties screen for each user. Is there any chance that "account disabled" or "user must change password at next logon" is checked? For our PDC, "user must change password" is the default and I have to make sure I change it every time I set up a new user.

Just a thought.
 
Yeah sorry checked all the basics!
even tried recreating a couple of accounts just as a test!
 
It has to do with the max/min age of the passwords. Microsoft recomends certain settings that tend to cause big problems... (Suprised?) In the min password age setting, set it to 0 (No minimum age) and try it again.

Cryptospy
 
no, tried that too. Strange thing is that the W98 clients on the network can log in no problem!
Only win2k clients can't! AAAAARRRGGGHHHH!!!!
 
Did you set a password for the user first then the first time they logon they will be prompted to change it?
You can set the password by right clicking the user and use set password.
 
You were not allowed to to log on locally since this right is not granted to regular user accounts. By default administrators have the right locally to a domain controller,but regular users do not.
To log on to server with a user account do this:
1-Log on as admin
2-open active directory users and computers and chose in the console tree,expand the chosen OU.
3-in the details pane, double click the user account you creats before.
4-Click the Member Of tab
5-Click Add
The Select Groups dialog box appears
6-scroll down in the top box to locate and click tex Print Operators.
7-Click Add, Ok
8-In console tree, click the Users folder.

hope this will help you.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top