Solved

permission problem in Active Directory

Posted on 2008-06-18
4
190 Views
Last Modified: 2010-03-17
The problem that I have is the domain controllers OU is not showing when I login as a domain admin. If I run a search nothing is found but if viewed with advance features you can see the domain controllers OU and the Infrastructure icon but both are displayed as windows icon. The domain controllers OU is Unknown under type and the infrastructure is infrastructure Update
If I login in as a domain administrator everything is normal.
When looking at any built in group membership for all the administrators icons are greyed out.

We have 4 DCs, 2x2003 and 2x2003r2 in a fully 2003 environment.
All domain controllers accounts and administrators accounts are stored in the default Domain Controllers OU.
0
Comment
Question by:AndyinJapan
  • 2
4 Comments
 
LVL 21

Accepted Solution

by:
mcsween earned 250 total points
ID: 21819135
run a DCDiag on each domain controller and post the output here (not all 4 if they are pretty much the same)
0
 
LVL 38

Assisted Solution

by:ChiefIT
ChiefIT earned 250 total points
ID: 21824709
You should first understand that the Domain controllers is not an Organizational Unit (OU). It is a Common Name folder (CN). Common Name folders are built into the system. I believe the Infrustructure folder is as well.

Group policy was not meant to be involked on a CN folder. Nor, was that CN folder meant to go to a subdirectory of another folder. It was meant to be in the root of the Domain Schema.

I don't know what we are going to have to do in order to fix your issue. Messing with these folders by deleting them or moving them should have given you an access denied. You might try dragging these two back into the domain root of ADUC.

But, I believe to fix these issue, you might have to use the NTDSutil.

0
 

Author Comment

by:AndyinJapan
ID: 21836165
Hi Guys,
First, many thanks for your help on this one but in end I sorrted it out.....I gave myself full permissions over the OU in question and alll returned to normal as well as the greyout user icons. Not sure what happened here but its ok now anyway!

0
 
LVL 38

Expert Comment

by:ChiefIT
ID: 21836175
Glad to here you got it fixed:

0

Join & Write a Comment

[b]Ok so now I will show you how to add a user name to the description at login. [/b] First connect to your DC (Domain Controller / Active Directory Server) SET PERMISSIONS FOR SCRIPT TO UPDATE COMPUTER DESCRIPTION TO USERNAME 1. Open Active …
Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now