Discussion in 'Active Directory' started by newbie admin, Jan 25, 2006.

  1. newbie admin

    newbie admin Guest

    the user account belongs to a group dbadmin( created by me), dbadmin is a
    member of the faulty member server's administrator (local group of course)

    this user can't logon successfully, either at the server's console or
    remotely, after click "login", a cmd prompt says"the command prompt has been
    disabled by your administrator", then he was log out automatically.

    But, another account, which is a member of both dbadmin and
    DomainAdmin(default ad group of course), he can login normally!

    I was driven mad! Please give some hints. Thanks!
    newbie admin, Jan 25, 2006
  2. newbie admin

    Paul Bergson Guest

    The problem appears to deal with a group policy against certain individuals
    but not against the Domain Admin. Perhaps someone setup a login script or
    disabled a function against this computer for non-admins. Go to Active
    Directory Users and Computers and find the OU that holds the for the member
    server and right click select properties and select the group policy tab.
    Browse through this and (You could load the group policy management console)
    see if you can find any policies that pertain to this setting. You could
    also try using the Resultant Set Of Policicies Snap-In and try and determine
    the issue.

    See if the links are of any help:;en-us;887303
    Paul Bergson, Jan 25, 2006
  3. check policies that apply to that user either in AD or on the local server


    # Jorge de Almeida Pinto #
    MVP Windows Server - Directory Services
    Jorge de Almeida Pinto [MVP], Jan 25, 2006
