Computing.Net > Forums > Windows Server 2003 > users can't login on DC

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

users can't login on DC

Reply to Message Icon

Name: Johanovitch
Date: March 24, 2005 at 03:17:57 Pacific
OS: W2K3
CPU/Ram: 1g
Comment:

Hello, I've setup a domain with roaming profiles for the users.
All is working fine, except that domain users cannot login on the Domain Controller.
The only solution I found so far is to make the users member of the domain admins-group, but that is not a good idea, as the users are then able to mess with the domain settings.

is there another way that domain users can login in a restricted way on the DC?

Johan



Sponsored Link
Ads by Google

Response Number 1
Name: Curt R
Date: March 24, 2005 at 04:18:42 Pacific
Reply:

I don't know why anybody would want to allow users to login locally on a server. I'm hoping this is just a test environment because doing so in the "real world" is asking for trouble.

Check the security policies. I'm not sure which one offhand but if you look through, you'll find the setting for allowing users to log on locally. That's where you choose who to allow to log onto the console. It's likely in the Local Security Policy on the server. If not there, check the Domain level GPO.


0

Response Number 2
Name: Glen
Date: March 24, 2005 at 07:23:50 Pacific
Reply:

The reason that the users can not log into a DC locally is a very good one. If you allow them to log on they have access to a number of things you don't want them to have access. Why in the world would you even consider letting them log in locally? If you don't have enough computers for them to log in from their own machines then you don't need a domain in the first place.



0

Response Number 3
Name: Dave_A
Date: March 24, 2005 at 15:13:42 Pacific
Reply:

Ill echo the above, unless you mean through a Terminal Session?


0

Response Number 4
Name: heropsycho2177
Date: March 24, 2005 at 19:51:49 Pacific
Reply:

Not even a terminal session is a good justification. Users should not be logging on to a domain controller in any fashion interactively. Do you really want your DC to go down because over something like some idiot user surfed a pr0n site with a malicious Active X or Java script?! What if the DC were breached in such a manner, and hackers then could get all the user accounts, etc.?

I know extra computers can be costly, but what will it cost for you or a contractor to fix a broken DC and possibly a breached network in labor and any loss of productivity caused in the process?

"...but in my defense, it was dark, I was drunk, and it was delicious!"


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows Server 2003 Forum Home


Sponsored links

Ads by Google


Results for: users can't login on DC

2003 terminal server - can't log on www.computing.net/answers/windows-2003/2003-terminal-server-cant-log-on/2134.html

can't login www.computing.net/answers/windows-2003/cant-login/8247.html

Can't log on local www.computing.net/answers/windows-2003/cant-log-on-local/4213.html