Assign "Log On locally" Rights to Windows 2000 Domain Controller
ID: Q234237
|
The information in this article applies to:
-
Microsoft Windows 2000 Advanced Server
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 2000 Datacenter Server
-
Microsoft Windows 2000 Server
SUMMARY
This article describes how to assign "Log on locally" rights for users and groups to Windows 2000-based domain controllers.
MORE INFORMATION
By default, the account operators, administrators, backup operators, print operators, server operators, Internet guest account, and Terminal Services user account are assigned the right to log on locally to a Windows 2000-based domain controller. You can use the Microsoft Management Console Group Policy Editor snap-in in your Windows 2000 Server-based computer to assign "Log on locally" user rights to other users and groups:
- Click Start, click Run, type mmc, and then press ENTER.
- Click Console, and then click Add/Remove Snap-in, click Add, and then double-click Group Policy snap-in.
- Click Browse for the group policy object, and then
double-click the folder for your domain controller.
- NOTE: To give users and groups "log on locally" permissions to specific domain controllers, in this step, replace "Default Domain Controllers Policy" with the "Local Policy" of the domain controller.
Double-click Default Domain Controllers Policy, click Finish, click Close, and then click OK.
- Click Default Domain Controllers Policy, double-click the Computer Configuration branch to expand it, and then double-click the Windows Setting branch to expand it.
- Double-click the Security Settings branch to expand it, and then double-click the Local Policies branch to expand it.
- Double-click the User Rights Assignment branch to expand it, double-click the Log On Locally branch to expand it, and then click Add.
- Click the users or groups you want to add, click OK, and then click OK.
- Quit the Group Policy Editor snap-in by clicking
Console, clicking Exit, and then clicking No.
NOTE: You do not have to save the console settings for the change to take effect. Active Directory replication must also occur between all domain controllers, and this could take up to 3 hours unless replication is forced.
Additional query words:
Keywords : kbnetwork kbtool
Version : WINDOWS:2000
Platform : WINDOWS
Issue type : kbhowto
|