Solved

Domain Admin Members have limited Domain admin permissions

Posted on 2006-11-20
4
212 Views
Last Modified: 2010-04-18
I recently inherited a network.  My account is a member of Domain Admins and Domain Admins are a member of the local administrator's group on each machine.  However, our permissions are limited.  For example, I tried to launch Device Manager as myself (a member of Domain Admins) on a local and was told I do not have the privilige.  I had to log in as the Domain Administrator Account.  There are three Group Policies on the network that I haven't been able to go through yet, but I was hoping you might point me in the right direction.
0
Comment
Question by:scubaed69
  • 2
4 Comments
 
LVL 31

Expert Comment

by:Toni Uranjek
ID: 17981356
Use GPMC or gpresult to find out which policies are in effect. There might be domain wide policy which prohibits  access to Control Panel. If you have only three policies defined you won't have to much work to review settings.

You are looking for User Configuration policy in Control Panel.
0
 
LVL 48

Accepted Solution

by:
Jay_Jay70 earned 500 total points
ID: 17982849
just move your user out of the range of any policy and try again, quick way to see if its a policy or not
0
 

Author Comment

by:scubaed69
ID: 17984447
I couldn't find the policy blocking me.  Everything I checked said not configured.  So, I created a new OU, blocked inheritance to it and placed the neccesary accounts in the OU. This seems to have solved the issue.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17984470
it was most probably the default domain policy that has some settings in it
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that. In this Article I'll show how to deploy printers automatically with group policy and then using security fil…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now