Solved

Is it possible to access network computers with domain admin privleges and not local privleges?

Posted on 2008-10-23
3
262 Views
Last Modified: 2012-05-05
I'm trying to access some network computers via c$..,  I have access to most but there's a few I cannot access.. Is there away I can access these computers without physically jumping from machine to machine adding myself to the local permissions?
0
Comment
Question by:hotrobb97
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 2

Expert Comment

by:armynt4
ID: 22789947
Doesn't seem like all the machines are correctly members of the domain.  The domain admin is automatically added to the local admin group when you add a machine to the domain.  If you cannot access the admin share there may be a problem with domain membership or a GPO that is restricting access.  Check Resultant Policy in AD to see what policy settings may be restricting you from admin shares.
0
 
LVL 58

Expert Comment

by:tigermatt
ID: 22790084

It sounds to me as though the 'Domain Admins' group has been removed from membership of the problematic machine's local Administrators group.

You can use Restricted Groups to force the Domain Admins group back as a member of the Administrators group, which should restore the permissions to network logins.

http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

-tigermatt
0
 
LVL 5

Accepted Solution

by:
gratex_ssd earned 125 total points
ID: 22790453
Did you try to ping them, eventally to do nmap scan - if there is not firewall enabled ? (you need minimaly 445/TCP open)

If it looks like firewall problem there is a solution - not to physicaly go to every bad behaved comp:

Make GPO that shuts "Windows Firewall" at your member workstations...
Wait a while (it takes more than 90 minutes to deploy this GPO -> because GPO is "pop" from client...
and then you can try...
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question