Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Is it possible to access network computers with domain admin privleges and not local privleges?

Posted on 2008-10-23
3
Medium Priority
?
286 Views
Last Modified: 2012-05-05
I'm trying to access some network computers via c$..,  I have access to most but there's a few I cannot access.. Is there away I can access these computers without physically jumping from machine to machine adding myself to the local permissions?
0
Comment
Question by:hotrobb97
3 Comments
 
LVL 2

Expert Comment

by:armynt4
ID: 22789947
Doesn't seem like all the machines are correctly members of the domain.  The domain admin is automatically added to the local admin group when you add a machine to the domain.  If you cannot access the admin share there may be a problem with domain membership or a GPO that is restricting access.  Check Resultant Policy in AD to see what policy settings may be restricting you from admin shares.
0
 
LVL 58

Expert Comment

by:tigermatt
ID: 22790084

It sounds to me as though the 'Domain Admins' group has been removed from membership of the problematic machine's local Administrators group.

You can use Restricted Groups to force the Domain Admins group back as a member of the Administrators group, which should restore the permissions to network logins.

http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

-tigermatt
0
 
LVL 5

Accepted Solution

by:
gratex_ssd earned 375 total points
ID: 22790453
Did you try to ping them, eventally to do nmap scan - if there is not firewall enabled ? (you need minimaly 445/TCP open)

If it looks like firewall problem there is a solution - not to physicaly go to every bad behaved comp:

Make GPO that shuts "Windows Firewall" at your member workstations...
Wait a while (it takes more than 90 minutes to deploy this GPO -> because GPO is "pop" from client...
and then you can try...
0

Featured Post

Ask an Anonymous Question!

Don't feel intimidated by what you don't know. Ask your question anonymously. It's easy! Learn more and upgrade.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question