In an attempt to make our child domains more “secure”, we went into one of the DCs and into “Domain Controller Security Policy”. We set the “Deny Logon Locally” option to a couple groups. The system is now very secure and will not even let the Administrator account log on to it locally stating the users are denied this option at logon. I still have full access to the hard drives and several of the MMC options (Active Directory Users and Computers for example) from the parent domain. Is there any way to get around this? Microsoft Knowledge Base didn’t have anything. Thank you very much for your time,
Jeff