Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Adding Domain user as local administrator on computer not retaining

Posted on 2011-03-25
8
Medium Priority
?
919 Views
Last Modified: 2012-05-11
Hello,

I will try to make as much sense of this that I can. I just started maintaining a small network which has a Windows 2003 server and 5 workstations. I haven't had the opportunity yet to fully dig into how their server was configure by the previous administrator.

I recently added a new laptop to the domain with a new user. I added the domain admin AND the new domain user as a local administrator on the laptop through the Control Panel>User Accounts interface. A couple days later the user was unable to download and update Flash, insufficient privileges. I noticed he was no longer a local admin on the laptop, neither was the domain admin. I added both the domain admin and the new domain user as administrators again on the local machine and all was well. A couple days later, again the user could not perform certain actions. And again the settings in the User Accounts did not retain.

What could be causing this? Is it a GPO on the server?

Any advice would be appreciated.
0
Comment
Question by:clraymond
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
8 Comments
 
LVL 30

Expert Comment

by:Randy Downs
ID: 35216522
If they log on to the domain then they will have the privileges you setup on the domain users. That's really an advantage of using a domain.
0
 
LVL 8

Expert Comment

by:tonyperth
ID: 35216791
I personally would check for a log in script that sets the local admin.  I have seen some techies put a script in that deletes all local admins except the actual local administrator acocunt.  the script could of course be anywhere in AD or more likely the profile script.

Cheers,

Tony
0
 
LVL 6

Assisted Solution

by:mattconroy
mattconroy earned 200 total points
ID: 35216821
Group Policy is the only thing that can do this.
0
Does Your Cloud Backup Use Blockchain Technology?

Blockchain technology has already revolutionized finance thanks to Bitcoin. Now it's disrupting other areas, including the realm of data protection. Learn how blockchain is now being used to authenticate backup files and keep them safe from hackers.

 
LVL 57

Accepted Solution

by:
Mike Kline earned 300 total points
ID: 35216837
Yes probably being pushed via restricted groups; you can see how that is done here:   http://www.frickelsoft.net/blog/?p=13

Run an RSoP report and you will be able to see what policies are being applied.

Thanks

Mike
0
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 35216897
You can run an RSOP report by opening up command prompt and typeing rsop.msc

Check under computer config\windows settings\restricted groups.
0
 
LVL 44

Expert Comment

by:Amit
ID: 35217961
Check Default Controller Domain policy. It seems Domain admin is part of restricted group. But why you are giving domain admin to user. It is unsafe as you have giving full rights for whole domain. Local admin rights are enough. As you added the user to domain admin already, admin count is now changed to 1. You can make it 0 by using adsiedit.msc tool.

It is by design, that AD check for protected groups and it is added as restricted group, it will remove it automatically. You first need to remove protected group from restrict policy as it is not recommended by MS. I have 4 days call for same issue with MS and finally we removed it from restricted gpo.
0
 
LVL 51

Expert Comment

by:Netman66
ID: 35219649
Mike is correct.  Group Policy Restricted groups is likely what is happening.

The last Admin obviously set that up wrong because, by default, the DA group gets added to the local Administrators group when you join the domain - and it should stay there.

You can also get information on where this is coming from by running gpresult /v on the laptop when it's connected to the domain.

0
 

Author Closing Comment

by:clraymond
ID: 35219917
Turns out there was a "Local Admin" GPO with a Restricted Group. That restricted group was the BUILTIN\Administrators. The new user that was having the issue was a member of the BUILTIN\Administrators group therefore we could not add him as a local admin on the machine.

What happen was before we could get in to configure his user, the employer attempted to set up his user, wanted to give the user some Administrative privileges and thought that by adding him in the BUILTIN\Administrators group he was giving him those rights. When we originally saw that this user was a member of that group we didn't think much of it (also because of budgetary reasons). BUT unfortunately being a member of that group restricted him from being a local admin.

Can't fully test this on the machine until Monday but that is what I am seeing the server end and so far this makes the most amount of sense. Thanks for all the help.

I am going to give Matt and Mike the credit. Thanks guys.
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question