Microsoft KB Archive/826903

= &quot;The local policy of this system does not permit you to logon interactively&quot; error message when you log on to your Windows 2000-based computer =

Article ID: 826903

Article Last Modified on 10/30/2006

-

APPLIES TO


 * Microsoft Windows 2000 Server
 * Microsoft Windows 2000 Professional Edition

-





SYMPTOMS
On a Microsoft Windows 2000-based computer, when you try to log on locally or try to log on to the domain, you receive the following error message:

The local policy of this system does not permit you to logon interactively.

If you try to log on to the domain as a domain administrator, you receive the following error message:

The system cannot log you on to this domain because the system's machine account in its primary domain is missing or the password on that account is incorrect.

If you use the Netdom.exe utility to reset the security channel to the domain controller, you receive the following error message:

The trust relationship between this workstation and the primary domain failed.

If you use the Nltest.exe utility to test the security channel to the domain controller, you receive the following error message:

Access denied.



RESOLUTION
To resolve this issue, follow these steps:  Restart the Windows 2000-based computer, and then run the Recovery Console. From the Recovery Console, type copy c:\winnt\repair\security c:\winnt\system32\config\security at the command prompt, and then press ENTER. At the command prompt, type exit, and then press ENTER to exit the Recovery Console and to restart the computer. Log on locally to the computer. Remove the computer from the domain, and then restart the computer.

To do this, follow these steps:  On your desktop, right-click My Computer, and then click Properties. Click the Network Identification tab, and then click Properties.</li> Under Member of, click Workgroup. Type the name of a workgroup, and then click OK two times.</li> Restart your computer.</li></ol> </li> In the Active Directory Users and Computers snap-in, delete the computer account. Wait for the deletion to replicate to all the domain controllers.</li> Rejoin the computer to the domain, and then restart the computer.

To do this, follow these steps: <ol style="list-style-type: lower-alpha;"> On your desktop, right-click My Computer, and then click Properties.</li> On the Network Identification tab, click Properties.</li> Under Member of, click Domain. Type the name of the domain that you want to join, and then click OK. You are prompted to provide a user name and password to join the computer to the domain.</li> Type the name and the password of an account that has permissions to join the computer to the domain, and then click OK two times.</li> Restart your computer.</li></ol> </li></ol>

Keywords: kberrmsg kbprb KB826903

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.