Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

March 30, 2004 12:00 AM

Logon Rejection

Windows IT Pro
InstantDoc ID #41778
Rating: (0)

A while back, a new administrator reset some computers' account passwords (i.e., not users' account passwords) in my company's domain. The next day, no one could log on to these machines. Users received the error message You do not have the right to log on to this computer. The computers even rejected members of their own local Administrators group.

I tried using the computers' local Administrator accounts to log on, but I received the same error message. To make matters worse, my boss couldn't log on to his notebook. (The administrator hadn't reset my boss's computer's account password.)

Our Group Policy—based security policy hadn't changed in the past month, so I couldn't figure out what was causing the problems. I suspected that some settings were corrupt, but I didn't know how I would reset them because I couldn't log on.

Finally, I accessed the computers through the network. I started the Telnet service and used a Telnet session to connect to the troublesome computers. Then, I entered

secedit 
/refreshpolicy machine_policy 
/enforce

at the remote machine's command prompt to force the computer to reapply the Group Policy from the domain controller—DC. (I needed to use the Secedit command because Windows 2000 doesn't reapply Group Policy if the policy hasn't changed.)

Users were then able to log on again—except my boss, whose computer still denied him access. I searched the Microsoft Knowledge Base and didn't find an obvious solution, although the Microsoft article "How to Set Logon User Rights by Using the NTRights Utility" (http://support.microsoft.com/?kbid=315276) gave me the idea to try the Microsoft Windows 2000 Server Resource Kit's Ntrights utility. I opened a command prompt on a different computer and entered

ntrights +r SeInteractiveLogonRight -u 
"everyone" -m \\<bosscomputer>

Voilà! The system accepted my boss's logon attempt.

I'm still not sure what caused the logon problems. In addition, I don't know what I would have done if I hadn't been able to connect to the systems remotely.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.