Solved

Domain admin problem

Posted on 2010-11-22
15
617 Views
Last Modified: 2013-12-02
We've already a couple of WIndows 7 machines, but i noticed something strange. Apparantly havind domain admin rights doesn't mean you have all full admin rights. Which is strange I think. How come and is there a way to change this?

Jvuz
0
Comment
Question by:jvuz
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 5
  • 2
  • +1
15 Comments
 
LVL 10

Expert Comment

by:David_Ingledew
ID: 34186872
What version is the AD?
0
 
LVL 21

Author Comment

by:jvuz
ID: 34186906
We're using Linux servers (Samba 3.4.3).
0
 
LVL 10

Expert Comment

by:David_Ingledew
ID: 34186962
Sorry I can't help - not experienced in that...my thoughts were that the policies didn't extend to some of the newer Win7 calls...
0
Optimum High-Definition Video Viewing and Control

The ATEN VM0404HA 4x4 4K HDMI Matrix Switch supports 4K resolutions of UHD (3840 x 2160) and DCI (4096 x 2160) with refresh rates of 30 Hz (4:4:4) and 60 Hz (4:2:0). It is ideal for applications where the routing of 4K digital signals is required.

 
LVL 1

Assisted Solution

by:clintonbrigham
clintonbrigham earned 200 total points
ID: 34187897
Windows Vista, 7, 2008 all use a "new" security feature called User Account Control. Basically regardless of what role you have assigned an account it is still only a basic user account until those privledges are elevated.  Here is the TechNet article that explains User Account Control:

http://technet.microsoft.com/en-us/library/cc772207(WS.10).aspx
0
 
LVL 51

Accepted Solution

by:
Netman66 earned 300 total points
ID: 34188582
When you joined this Samba domain, did the Domain Admin group get added to the local Administrators group?  I'm not certain it would do it automatically since it's not a Windows-based domain.  You may need to add this group manually.

Also, as was mentioned, you might need to turn off UAC for the Administrators if adding the group doesn't automatically take care of this.

0
 
LVL 21

Author Comment

by:jvuz
ID: 34189113
I'll have to check for the domain admins in the group administrators. I'll let you know tomorrow.
0
 
LVL 21

Author Comment

by:jvuz
ID: 34202967
The domain admin is in the administrators group.
If I disable the UAC, everyting works like it should be, but when I reenable it, I'm back to 0.
i'm afraid I'll have to turn of UAC. i don't want to, but if it doesn't work, I'll need to unless someone else has an idea.

Jvuz
0
 
LVL 51

Expert Comment

by:Netman66
ID: 34204649
You can selectively turn it off for only Administrators - this gives you peace of mind knowing that normal users still end up with UAC enabled.

How To is here:  http://www.howtogeek.com/howto/windows-vista/disable-user-account-controluac-for-administrators-only/

This policy setting is likely available from a server-side GPO (I don't have the ability to test it here), so that you don't have to go around to each machine.

Create a new GPO and attach it to the domain and make this single setting in that policy.

0
 
LVL 51

Expert Comment

by:Netman66
ID: 34205377
@jvuz - what did you ultimately end up doing?  If UAC was part of (or the entire) solution, then it's only fair to split points with clintonbrigham.

Please let us know and I can have this Q re-opened so that points can be fairly distributed.

0
 
LVL 21

Author Comment

by:jvuz
ID: 34207774
I turned UAC off, like you suggested. That's why I didn't split points. If you think I should split the points, no problem. Then you can reopen the question and I'll split the points.

Jvuz
0
 
LVL 51

Expert Comment

by:Netman66
ID: 34215094
In the interest of the spirit of this site, and because clintonbrigham mentioned UAC first before I specified how to turn it off, I would like to see a point split of 200 to him and 300 to me (only for providing more detail).

If you like, I can have a Mod reopen so you can redistribute the points - or you can do it yourself - let me know either way and I'll be happy to assist.

NM
0
 
LVL 21

Author Comment

by:jvuz
ID: 34215548
You may reopen the question and I'll divide the points regardingly.

jvuz
0
 
LVL 51

Expert Comment

by:Netman66
ID: 34220398
There you go!  Ready for you to distribute now.

0

Featured Post

Get MongoDB database support online, now!

At Percona’s web store you can order your MongoDB database support needs in minutes. No hassles, no fuss, just pick and click. Pay online with a credit card. Handle your MongoDB database support now!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Determining the an SCCM package name from the Package ID
In this post we will be converting StringData saved within a text file into a hash table. This can be further used in a PowerShell script for replacing settings that are dynamic in nature from environment to environment.
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question