?
Solved

Domain Users/Admin lose Local Admin and Remote Desktop permissions

Posted on 2008-06-12
2
Medium Priority
?
587 Views
Last Modified: 2013-11-21
Got a odd one I think.  I have a medimum sized network with several windows 2003 server and XP Pro SP2 PCs.  3 DCs, 2 Exchange, 4 Web Servers/Services and several File and SQL servers.  Up until yesterday afternoon everything was good.  We have several custom apps where domain users need to be in the local admin group to run specific apps.  Admins have their own domain admin account and domain user accounts.
  We just installed 2 Trigio servers and were informed that we needed to push the remote agent to the DCs to support training next week.  We pused as directed by the trainer, ok first mistake pushed to production boxes, but experienced issues.  Eventually installed via CD.  After a few hours we noticed that individual domain admin accounts could not RDP on to the 3 DCs but could still RDP to other domain servers.  This morning backups on 8 servers failed with authentication errors.  We created a seperate backupexec account with appropriate permissions to conduct backups.  Again it appears that the backupexec account has been removed from the local admin and backup groups on the individual servrs.
  We noticed that users who logged off or shutdown there computers were the one who lost local admin right but those who just locked their work station did not.  So it appears like a GPO issue.  I have checked the restricted groups GPO but it appears fine.  Any other ideas?
0
Comment
Question by:sbsitech
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 2

Accepted Solution

by:
geedoubleu earned 750 total points
ID: 21772357
Removing accounts from groups can be done by vbscript and other programs, but a GPO is more likely.

Use the GPO results Wizard to show exactly what settings are being applied, including any local GPO's.

Also check any security applications you are running that are "helpfully" restricting group membership.
eEye Retina Scanner is a classic example of a application that can do this.
0
 

Author Comment

by:sbsitech
ID: 21817999
Ran results wizard and found that the administrator entry in the restricted groups GPO had no entires which was the problem.  deleted administrator from restriced groups and added domian admins to local admins groups and things are humming along.  Thanks

Jim
0

Featured Post

Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question