Discussion in 'Windows Server' started by scptech, Jul 20, 2005.

    To allow a domain user access to a local workstation, does the user have to
    be added to the workstation explicitly, even if the user has domain admin

    Under what circumstances does the trust relationship between the workstation
    and the primary domain fail?
  2. Well, any time a domain user's credentials cannot be authenticated - eg. DC
    failure, connectivity issue, etc., that user will be denied network access
    to a domain member..

    By default, when a workstation joins an AD domain, the domain administrators
    group is added to the local machine administrators group; and the domain
    users group is added to the local machine users group. So as long as the
    machine is joined to the domain, you should not need to add domain users as
    local users unless you have changed or want to change the default behavior.

    Doug Sherman [MVP], Jul 20, 2005
    Thanks a lot.

