Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Error Message: The Local Policy of This System Does Not Permit You to Log on Interactively


This article applies to Windows 2000. Support for Windows 2000 ends on July 13, 2010. The Windows 2000 End-of-Support Solution Center is a starting point for planning your migration strategy from Windows 2000. For more information see the Microsoft Support Lifecycle Policy.

↑ Back to the top


Symptoms

When you add a group, such as, Domain Users, Everyone, or Authenticated Users, to the "Deny Logon Locally" user right, users that are members of those groups can no longer log on to certain computers. When a user tries to log on to the computer, the user may receive the following error message:

The Local policy of this system does not permit you to log on interactively.
The administrator of your system may find this behavior to be unexpected.

↑ Back to the top


Cause

This behavior may occur because the user (such as, the administrator, who is a member of a group that has been explicitly granted the "Logon Locally" user right) may also be a member of the preceding groups. Any of the preceding groups may deny users access to the computer in which case a policy that sets the denial of user rights takes precedence over a policy that enables user rights.

↑ Back to the top


Resolution

To work around this behavior, you can access the computer that is denying a user access by means of an administrative account situated on another client. Then you can use the Ntrights.exe program from the Microsoft Windows 2000 Resource Kit to remove the user from the "Deny Logon Locally" user right.

To perform this procedure, use the following (case-sensitive) syntax:
ntrights -m \\computer -u group or user to remove -r SeDenyInteractiveLogonRight

↑ Back to the top


Status

This behavior is by design.

↑ Back to the top


More Information

Most of the preceding problems occur when the Everyone group has been removed from the user right. You can use the Ntrights utility to add user rights.

For additional information about how to add a group back to the user right, click the article number below to view the article in the Microsoft Knowledge Base:

279664 How to Set Logon User Rights with the Ntrights.exe Utility

↑ Back to the top


Keywords: kberrmsg, kbprb, kbbillprodsweep, kb

↑ Back to the top

Article Info
Article ID : 276590
Revision : 4
Created on : 8/29/2018
Published on : 8/30/2018
Exists online : False
Views : 160