Local log on policy prohibits interactive logon

Asked By 200 points N/A Posted on -
qa-featured

Hi,

My computers are configured to allow Remote Desktop Connections. I am trying to log on via Remote Desktop Connection to one of my computers. The connection is established and I receive the log in window.

I however cannot log in.

When I fill in the user name and password, I get an error which says that the local policy of this system does not allow interactive you to log on interactively.

I have tried to log on using several different user accounts and I tried logging on from more than one computer on my network, but I keep getting the same error message on all computers. Please solve this.

Thanks!

Error message below:

Logon Message The local policy of this system does not permit you ti logon interactively. OK

Logon Message

The local policy of this system does not permit you to logon interactively.

OK

SHARE
Best Answer by JohnyGarcia
Best Answer
Best Answer
Answered By 0 points N/A #124841

Local log on policy prohibits interactive logon

qa-featured

Hello,

This error you are having occurs because the user account trying to access is not a member of the local Remote Desktop user group. What you can do is add the user to the user group:

  1. Click Start then go to Settings then go to Control Panel.
  2. Go to System then on the Remote tab, find Select Remote Users and then click it.
  3. Click Add type in the user account name then OK.
  4. To add more than one user, just put a semi colon in between the names.

You should also make sure there are sufficient privileges so that the user can log in:

  1. Go to Start then Run.
  2. In Run type secpol.msc and click OK.
  3. Go to Local Policies then User Right Assignment.
  4. Look at the right side and double click Allow logon through Terminal Services and make sure the Remote Desktop User Group is listed.
  5. Click OK.
Answered By 0 points N/A #124842

Local log on policy prohibits interactive logon

qa-featured

Hi Faith West,

This problem appears mostly when you try to add some group or domain user to some denial login policy. All those users who are members and associated with these groups cannot log on to the system.

And whenever a user try to log on to such system the error message appeared as you have mentioned. Another possibility could be that the administrator of the system may also be a member of the same restricted group.

To resolve the issue, if the current administrator also couldn’t logon to the system, use any other client on the LAN and then login as an administrator account, run the Ntrights.exe file from the MS Windows 2000 Kit to remove a user.

To execute this operation use this syntax as it is (case sensitive)

ntrights -m \computer -u group or user to remove -r SeDenyInteractiveLogonRight

Related Questions