"Everyone" can add or remove themselves from Domain Administrator account whenever they want to

Posted on 2004-11-23
Last Modified: 2010-04-14
I am running a mixed mode network and I currently have 2 W2k AD DC and 1 WINNT PDC. I am only running 4 limited Group Policies and none of these effect security. I notice that the Everyone group has the ability to Add/Remove themselves from the Domain Administrator account. I have explicitly denied this and within a short time (maybe through replication or policy refresh) it returns as Approved. This is a major security fault please help. I am not sure if there is a default setting I am unaware of. On another side note I experienced the "The Local Policy of the system does not permit you to logon interactively" I used the ntrights.exe and was able to get back in but have since had this happen again. Looking through my GPO I do not see anything that would make this happen. I listed this because I am hoping they are somehow related. Any help would be appreciated.
Question by:fabres
    LVL 18

    Accepted Solution

    "The Local Policy of the system does not permit you to logon interactively"

    For this error you have to give the user rights in the local security policy on the client.


    computer config- windows settings- security- local policies- user rights assignment- log on locally
    LVL 18

    Expert Comment

    I assume you mean that users are able to add themselves to the domain admin group?

    Go into active directory users and computers- users- then click on the domain admin group

    The members tab will list the members and the security tab will list who has rights to this group. You need to remove the everyone group from this security tab.

    Featured Post

    What Is Threat Intelligence?

    Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

    Join & Write a Comment

    NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
    Real-time is more about the business, not the technology. In day-to-day life, to make real-time decisions like buying or investing, business needs the latest information(e.g. Gold Rate/Stock Rate). Unlike traditional days, you need not wait for a fe…
    Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
    Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now