by default, win2k domain controller only allow proper user rights to logon locally, this user groups include: adminstrators, printer operator, account operator, etc. so you have two way:
1; logon as users from one of the group, or add the user to the group.
2: modify local security policy and domain controller security policy to allow specified users to have logon locally rights