Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Local policy does not permit you to log on??

Status
Not open for further replies.

mquinn0908

Technical User
Jul 3, 2002
335
US
I have a W2K client who when trying to log onto the domain receives the following message: "can not log on because computer's account in the primary domain is missing or password is incorrect". I know the password is correct so I tried to log onto the local computer as the administrator so I could rejoin the domain and I get the message that the local policy does not allow you to log on interactively. On the server I see the computers name but when you try to access it the message appears that the trust relationship failed. The only way I can access the machine is to unplug the network cable and have it log on with cached information. I checked the local security policy on the machine and there is no one in the deny log on locally policy and the adminstrator is in the allow log on local policy. How can I fix this problem so I can log on locally and change the domain?
 
Just out of curiousity, are the computer account and user account in the same domain (not that it makes much difference).
Sounds like there's a problem with the computer account in the computer account domain - have you tried removing the problem pc from the computer account domain, joining the pc to a workgroup (any workgroup name, doesn't really matter...), deleting the computer account from the computer account domain and rejoining the pc to the computer account domain so that a new computer account is created?
 
Yes the computer account and user account are in teh same domain.

I have not tried to move it from a workgroup to domain because I am worried that I will not be able to access the machine at all since I can't log on locally.
 
Are you sure that when you tried to logon locally it was set to login to the local machine and not the domain? In other words on the startup screen if you hit options it shows a dropdown menu of what your trying to login to. Make sure it is login in to the local computer and not the domain. If you did check this then you need an domain administator to change the Gpo security settings that say let "X" group login local (were x is a group like users or guest).
 
Yes I made sure I was logging into the local machine and not the domain. I checked the security setting on the local machine and it is set to allow administrators to log on locally, however, the administrator of the local machine can not log on.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top