Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Is it possible to access network computers with domain admin privleges and not local privleges?

Posted on 2008-10-23
3
259 Views
Last Modified: 2012-05-05
I'm trying to access some network computers via c$..,  I have access to most but there's a few I cannot access.. Is there away I can access these computers without physically jumping from machine to machine adding myself to the local permissions?
0
Comment
Question by:hotrobb97
3 Comments
 
LVL 2

Expert Comment

by:armynt4
ID: 22789947
Doesn't seem like all the machines are correctly members of the domain.  The domain admin is automatically added to the local admin group when you add a machine to the domain.  If you cannot access the admin share there may be a problem with domain membership or a GPO that is restricting access.  Check Resultant Policy in AD to see what policy settings may be restricting you from admin shares.
0
 
LVL 58

Expert Comment

by:tigermatt
ID: 22790084

It sounds to me as though the 'Domain Admins' group has been removed from membership of the problematic machine's local Administrators group.

You can use Restricted Groups to force the Domain Admins group back as a member of the Administrators group, which should restore the permissions to network logins.

http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

-tigermatt
0
 
LVL 5

Accepted Solution

by:
gratex_ssd earned 125 total points
ID: 22790453
Did you try to ping them, eventally to do nmap scan - if there is not firewall enabled ? (you need minimaly 445/TCP open)

If it looks like firewall problem there is a solution - not to physicaly go to every bad behaved comp:

Make GPO that shuts "Windows Firewall" at your member workstations...
Wait a while (it takes more than 90 minutes to deploy this GPO -> because GPO is "pop" from client...
and then you can try...
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A quick step-by-step overview of installing and configuring Carbonite Server Backup.
In-place Upgrading Dirsync to Azure AD Connect
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question