[Samba] Unable to create GPO "Allow log on locally"

L.P.H. van Belle belle at bazuin.nl
Mon Aug 8 11:48:11 UTC 2016

> To reproduce just try to add "DOMAIN\Administrator" or
> "CLIENT\Administrator" to the GPO mentioned above with any recent RSAT
> Client on a Samba 4.4.5 DC.

I can not reproduce you problem, works fine here. ( also samba 4.4.5 ) 
I do this also for my "remote desktop" users. 

The group "domain admin" is added to BUILDIN\Adminstrators . 
I can, which any modification, login localy. ( NO RDP ) 

And to do this over RDP, you need do add a domain group to the local "Remote Desktop Users" group. 
And set the remote desktop service to automatic. 

Add this in the default domain policy or create a separated GPO for it. 
But the more GPO's the slower your login. 

And dont try this with COMPUTERNAME\Administrator, that one is disabled. 
Create a new admin (domain) add that one do domain admins and try again. 



More information about the samba mailing list