Win2k TSE (not a DC) in a Win2k AD (SBS2000) environment. I have allowed several users to logon to the TSE, but when I allowed the last user I get the dreaded "Local policy doesnot permit you to logon" error. I have triple-checked the domain policy, the domain controller policy and the local policy, and no users or groups are blocked whatsoever from logging on locally. Yes, they have been granted rights to logon to the term server on the Term Server tab on the user's properties, and the users are all members of the same security groups, and they all exist in the same container. Now, if I allow this user local admin rights on the TSE, they get in just fine. The only thing that has changed since I allowed the last user to logon successfully without any problems is that SP3 has been applied to the TSE and to the DC, which leads me to believe that this a SP3 bug - especially since my one Microsoft response confirms the behavior was repeatable on their test network. Has anyone else seen this? Any workarounds? __________________________________________________ Do you Yahoo!? Yahoo! News - Today's headlines http://news.yahoo.com ********************************************** This weeks sponsor 99Point9.com 99Point9 helps solve your unresolved technical server-based questions, issues and incidents. http://www.99point9.com *********************************************** For Archives, to Unsubscribe, Subscribe or set Digest or Vacation mode use the below link. http://thethin.net/citrixlist.cfm