G
Guest
Guest
Archived from groups: microsoft.public.win2000.active_directory (More info?)
Using Windows 2000 Server and Windows 2000 Professional client.
We have a network where the servers are part of a domain but the clients PCs
are not. The users use applications through a Citrix server.
I had a need to map a network drive and the quickest way to do it was to
join the client PC to the domain. Copied over the files, then deleted the
computer object through the Users and Computers AD app. After that, I could
not access the client PC. Attempting to log into the local machine results
in an error to the effect of 'The local policy of this system does not allow
you to logon interactively". And, after deleting the object, a user can not
log into the domain. The PC is inaccessible.
It appears that a vendor had set a group policy to disallow local logins to
domain members except to specific users (who never had access to this client).
Last Known Configuration did not solve the problem.
So, how can I do one of two things: either A.) alter the local policy on
the client without being able to access it, or B.) rejoin the PC to the
domain so I can apply a Group Policy? Deleting or changing the SID?
No user is currently able to log in to the PC, so anything with a registry
key, or somehow capturing it with the domain controller?
Thanks!
Using Windows 2000 Server and Windows 2000 Professional client.
We have a network where the servers are part of a domain but the clients PCs
are not. The users use applications through a Citrix server.
I had a need to map a network drive and the quickest way to do it was to
join the client PC to the domain. Copied over the files, then deleted the
computer object through the Users and Computers AD app. After that, I could
not access the client PC. Attempting to log into the local machine results
in an error to the effect of 'The local policy of this system does not allow
you to logon interactively". And, after deleting the object, a user can not
log into the domain. The PC is inaccessible.
It appears that a vendor had set a group policy to disallow local logins to
domain members except to specific users (who never had access to this client).
Last Known Configuration did not solve the problem.
So, how can I do one of two things: either A.) alter the local policy on
the client without being able to access it, or B.) rejoin the PC to the
domain so I can apply a Group Policy? Deleting or changing the SID?
No user is currently able to log in to the PC, so anything with a registry
key, or somehow capturing it with the domain controller?
Thanks!