Solved

Is it possible to access network computers with domain admin privleges and not local privleges?

Posted on 2008-10-23
3
256 Views
Last Modified: 2012-05-05
I'm trying to access some network computers via c$..,  I have access to most but there's a few I cannot access.. Is there away I can access these computers without physically jumping from machine to machine adding myself to the local permissions?
0
Comment
Question by:hotrobb97
3 Comments
 
LVL 2

Expert Comment

by:armynt4
ID: 22789947
Doesn't seem like all the machines are correctly members of the domain.  The domain admin is automatically added to the local admin group when you add a machine to the domain.  If you cannot access the admin share there may be a problem with domain membership or a GPO that is restricting access.  Check Resultant Policy in AD to see what policy settings may be restricting you from admin shares.
0
 
LVL 58

Expert Comment

by:tigermatt
ID: 22790084

It sounds to me as though the 'Domain Admins' group has been removed from membership of the problematic machine's local Administrators group.

You can use Restricted Groups to force the Domain Admins group back as a member of the Administrators group, which should restore the permissions to network logins.

http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

-tigermatt
0
 
LVL 5

Accepted Solution

by:
gratex_ssd earned 125 total points
ID: 22790453
Did you try to ping them, eventally to do nmap scan - if there is not firewall enabled ? (you need minimaly 445/TCP open)

If it looks like firewall problem there is a solution - not to physicaly go to every bad behaved comp:

Make GPO that shuts "Windows Firewall" at your member workstations...
Wait a while (it takes more than 90 minutes to deploy this GPO -> because GPO is "pop" from client...
and then you can try...
0

Join & Write a Comment

[b]Ok so now I will show you how to add a user name to the description at login. [/b] First connect to your DC (Domain Controller / Active Directory Server) SET PERMISSIONS FOR SCRIPT TO UPDATE COMPUTER DESCRIPTION TO USERNAME 1. Open Active …
Resolve DNS query failed errors for Exchange
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now