It is enough to add a user account to the local policy Allow log on locally on your server. In some cases, you may allow a user to log on to the domain controller/ Windows Server hosts over RDP or locally. (Get-ADUser maxbak -Properties LogonWorkstations).LogonWorkstations Using the Get-ADUser PowerShell cmdlet, you can display a list of computers a user is allowed to log on to (by default, the list is empty): The list of users who are allowed to log in via Remote Desktop is set in the same GPO section using the Allow logon through Remote Desktop Services option.Īnother reason why you can see “ The sign-in method you are trying to use isn’t allowed” error is when a list of computers a user is allowed to log on to is restricted in the LogonWorkstations user attribute in AD (read more here). Note that users can use interactive RDP sessions to connect to a Windows device (if RDP is enabled on that device) despite being denied local logon. In my case, anonymous local logon under the Guest account is denied on the computer. The policy is called Deny log on locally. After making the changes, update Group Policy settings using the gpupdate /force command (no reboot required).Īlso, note that there is another policy to prevent local interactive sign-in to Windows in the same GPO section.To do it, just remove Users group from the policy settings For example, you prevent non-admin users to log on to the device. To do it, click Add User or Group and select the users you want to add. You can allow local sign-in for other users or groups.On servers running Windows Server with the Active Directory domain controller role (ADDS), interactive sign-in is allowed for the following groups: For example, local sign-in is allowed for the following user groups on workstations running Windows 10 and servers running Windows Server 2022,2019,2016: Depending on the operating system and computer role, the list of groups allowed to sign-in locally may vary.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |