Solved

Domain admin problem

Posted on 2010-11-22
15
610 Views
Last Modified: 2013-12-02
We've already a couple of WIndows 7 machines, but i noticed something strange. Apparantly havind domain admin rights doesn't mean you have all full admin rights. Which is strange I think. How come and is there a way to change this?

Jvuz
0
Comment
Question by:jvuz
  • 5
  • 5
  • 2
  • +1
15 Comments
 
LVL 10

Expert Comment

by:David_Ingledew
ID: 34186872
What version is the AD?
0
 
LVL 21

Author Comment

by:jvuz
ID: 34186906
We're using Linux servers (Samba 3.4.3).
0
 
LVL 10

Expert Comment

by:David_Ingledew
ID: 34186962
Sorry I can't help - not experienced in that...my thoughts were that the policies didn't extend to some of the newer Win7 calls...
0
Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

 
LVL 1

Assisted Solution

by:clintonbrigham
clintonbrigham earned 200 total points
ID: 34187897
Windows Vista, 7, 2008 all use a "new" security feature called User Account Control. Basically regardless of what role you have assigned an account it is still only a basic user account until those privledges are elevated.  Here is the TechNet article that explains User Account Control:

http://technet.microsoft.com/en-us/library/cc772207(WS.10).aspx
0
 
LVL 51

Accepted Solution

by:
Netman66 earned 300 total points
ID: 34188582
When you joined this Samba domain, did the Domain Admin group get added to the local Administrators group?  I'm not certain it would do it automatically since it's not a Windows-based domain.  You may need to add this group manually.

Also, as was mentioned, you might need to turn off UAC for the Administrators if adding the group doesn't automatically take care of this.

0
 
LVL 21

Author Comment

by:jvuz
ID: 34189113
I'll have to check for the domain admins in the group administrators. I'll let you know tomorrow.
0
 
LVL 21

Author Comment

by:jvuz
ID: 34202967
The domain admin is in the administrators group.
If I disable the UAC, everyting works like it should be, but when I reenable it, I'm back to 0.
i'm afraid I'll have to turn of UAC. i don't want to, but if it doesn't work, I'll need to unless someone else has an idea.

Jvuz
0
 
LVL 51

Expert Comment

by:Netman66
ID: 34204649
You can selectively turn it off for only Administrators - this gives you peace of mind knowing that normal users still end up with UAC enabled.

How To is here:  http://www.howtogeek.com/howto/windows-vista/disable-user-account-controluac-for-administrators-only/

This policy setting is likely available from a server-side GPO (I don't have the ability to test it here), so that you don't have to go around to each machine.

Create a new GPO and attach it to the domain and make this single setting in that policy.

0
 
LVL 51

Expert Comment

by:Netman66
ID: 34205377
@jvuz - what did you ultimately end up doing?  If UAC was part of (or the entire) solution, then it's only fair to split points with clintonbrigham.

Please let us know and I can have this Q re-opened so that points can be fairly distributed.

0
 
LVL 21

Author Comment

by:jvuz
ID: 34207774
I turned UAC off, like you suggested. That's why I didn't split points. If you think I should split the points, no problem. Then you can reopen the question and I'll split the points.

Jvuz
0
 
LVL 51

Expert Comment

by:Netman66
ID: 34215094
In the interest of the spirit of this site, and because clintonbrigham mentioned UAC first before I specified how to turn it off, I would like to see a point split of 200 to him and 300 to me (only for providing more detail).

If you like, I can have a Mod reopen so you can redistribute the points - or you can do it yourself - let me know either way and I'll be happy to assist.

NM
0
 
LVL 21

Author Comment

by:jvuz
ID: 34215548
You may reopen the question and I'll divide the points regardingly.

jvuz
0
 
LVL 51

Expert Comment

by:Netman66
ID: 34220398
There you go!  Ready for you to distribute now.

0

Featured Post

Master Your Team's Linux and Cloud Stack

Come see why top tech companies like Mailchimp and Media Temple use Linux Academy to build their employee training programs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
In this article, I will show you HOW TO: Perform a Physical to Virtual (P2V) Conversion the easy way from a computer backup (image).
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum editing capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question