The identity user needs this permission to run correctly. Sometimes if the GPO permissions have been limited this will get disabled.
If you are trying to set up users or groups to be part of the "Log on as a batch job" local security policy for a workspace server configuration, you might notice that you do not have access to modify the policy from a Windows Domain Controller.
The reason for this is that on a Domain Controller, security policies are managed from the Group Policy Management Editor instead of from the Local Security Policy settings.
To modify the "Log on as a batch job rights" settings on a Domain Controller, follow the steps below:
- Under Windows, select Start ► Administrative Tools ► Group Policy Management.
- Click to expand Forest and Domains, and then expand your domain name.
- Expand Domain Controllers
- Right-click Default Domain Controllers Policy and select Edit.
- In the Group Policy Management Editor dialog box, under Computer Configuration, expand Policies, Windows Settings, Security Settings, and Local Policies, and then click User Rights Assignment.
- Double-click Log on as a batch job permissions and add your users or groups.