This is usually because the Group Policy forbids that user or group from logging in.
You should also check under "User Rights Assignment" that your user or group is listed under the "Allow logon locally setting"
After that check policies like "Deny logon locally". Any user or group there won't be able to login, so make sure you remove them if they are supposed to have access.
method, isn, info, administrator, active, directorythis, forbids, user, logging, quot, gpedit, msc, administrative, edit, default, domain, thatcheck, policies, logon, locally, login,