I tried to add a user in AD yesterday, and when I added a
new user that was only a member of the domain users group
it created the object fine but when I logged off and try
to logon as that user it gave me the message "local system
policy prevents you from logging in interactivly", I know
that according to the MS 70-215 test there answer to this
situation is "give the user rights to log on locally". I
do not want to do this. I want them to be able to log on
to the domain. Next, I copied my account, the
administrator, I was able to log on as them just fine to
the domain, but now they are an administrator. That is
not good. I need to be able to add them as a domain user
only. How can this be done?