Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read

Sponsored Links



"You cannot log on because the logon method you are using is not allowed on this computer"

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 30-05-2009
Member
 
Join Date: Jan 2009
Posts: 145
"You cannot log on because the logon method you are using is not allowed on this computer"

This is the error I am getting when I try to log in on the DC with a user which is not a member of the Domain Admin group. If I log in with the domain Administrator user and assign the domain admin group to the user it logs in normally. I have tried to create a different group but still the same.

Reply With Quote
  #2  
Old 30-05-2009
Member
 
Join Date: Oct 2004
Posts: 1,345
Re: "You cannot log on because the logon method you are using is not allowed on this computer"

I think that the user has to be in the domain admin group. It is a domain controller, so why would you want a non-admin to log onto a domain controller? Can you tell me whether this is a Terminal Server in Application mode? If that is the case, then in order to allow a non-domain admin account to logon on to a Terminal Server, the account would need to be in the Terminal Services group, have log on locally rights, as well as log on interactive rights?
Reply With Quote
  #3  
Old 31-05-2009
Member
 
Join Date: Oct 2005
Posts: 2,356
The easiest method to allow non-priviledge users to log onto a Domain Controller is to add them to the "Remote Desktop Users" domain global group. In general, it is not suggested to use it, although, primarily due to security implications.
Reply With Quote
  #4  
Old 11-07-2009
Member
 
Join Date: Jul 2009
Posts: 3
Re: "You cannot log on because the logon method you are using is not allowed on this computer"

I assigned "Remote Desktop Users" to a user account but the user is still not able to login. I had a look into Local Security Policy->Security Settings/Local Policies/User Rights Assignment/Allow log on locally, Remote Desktop Users is not in the list. The Add User or Group button is disabled

Please advise what security group should I give to the user so that the user can login to server to perform some administrator tasks such as reset password.
Reply With Quote
  #5  
Old 11-07-2009
Member
 
Join Date: Nov 2005
Posts: 631
Re: "You cannot log on because the logon method you are using is not allowed on this computer"

I think that a non-domain admin would not need to logon to a domain controller to perform such tasks as resetting password. You can try to install the adminpak.msi tools on the users workstation and once it is installed, instruct the user to simply run Active Directory Users and Computers, select the OU they have been delegated permissions, and they will be able to change or reset password.
Reply With Quote
  #6  
Old 12-07-2009
Member
 
Join Date: Jul 2009
Posts: 3
Thanks for your simple step by step explaination.

I created a MMC added with snap shots Event Viewers and Active Directory Users and COmputers on my AD Domain Server 2008, save it as Users mode-Full access (for testing purpose).

I copied the MMC to another non-AD Server 2008 which is login as the same domain. I opened the MMC, i can view the event viewers. But when i click on Active Directory Users and COmputers on the left panel, "MMC could not create the snap-shot" was shown on the right panel.
Please advise.

Also, if i really want to create a user with "Remote desktop" security group, but that security group is not listed in the local group policy, is there a way?

Thanks
Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Tags: ,



Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: ""You cannot log on because the logon method you are using is not allowed on this computer""
Thread Thread Starter Forum Replies Last Post
"Not allowed to play this game" error message in windows 7 vijay nahur Operating Systems 4 11-01-2011 06:48 PM
"xxx" is not set up to establish a connection on port "world wide web service (HTTP)" with this computer. NicholasGrin Vista Help 1 13-05-2010 03:46 AM
Music player of nokia 5220 shows "Not allowed" Message when playing muisc MABON Portable Devices 5 23-12-2009 04:27 PM
SOLVED error 1385 "Logon failure: the user has not been granted the requested logon type at this computer Kaalan Windows XP Support 5 26-10-2009 07:20 PM
Joomla "Direct Access to This Location Is Not Allowed" Error Ananias Technology & Internet 3 22-05-2009 02:35 PM


All times are GMT +5.5. The time now is 07:15 PM.