I have Windows server 2003 joined to a domain (it is not a DC). I am looking to deny “log on locally” to the functional accounts (they are domain accounts)that are members of the local admins group on this server. I denied at the local sec policy level but can still log on as those users. Can this be done at the local sec policy level or does it have to be set at the domain level policy? Thanks.