Solved

Domain Admin Account not getting Domain Admin rights on 2008R2 Remote Desktop Server

Posted on 2014-02-04
6
663 Views
Last Modified: 2014-03-05
I have two domain admin accounts that log into 3 remote desktop servers, on 2 of the servers they can see all printers that have a security setting to only allow users in a Printers_x group or Local domain admins.
On 1 of the remote desktop server, they can only see the printers if they are added directly to the printer.  I have tried even adding domain admins to the printer and they still cant see it.
I have checked, doman admins are in local admins group.

I ran a whoami /groups /fo list as the user and it shows they are in the local administrator and domain administrator, but the printers still do not show up.

If I add the domain admin account to the Printers_x group, the printers show up.

It's like the Remote Desktop Server is not "seeing" that the user is a domain admin.

I have checked Local Policies Security Settings and they are the same.
I also have UAC the same on both machines.
0
Comment
Question by:BFanguy
  • 4
  • 2
6 Comments
 
LVL 36

Expert Comment

by:Mahesh
ID: 39833653
have you mapped printers through some script \ GP Preferences so that if user is member of particular group, then only printer will get mapped ?

How you are mapping printers ?

Mahesh
0
 

Author Comment

by:BFanguy
ID: 39834204
not mapping printers, no GP preferences.

as far as I know all 3 remote desktop servers are the same.
0
 
LVL 36

Expert Comment

by:Mahesh
ID: 39834894
When you take RDP of 3rd server have you selected Printers checkbox on show options\local resources page in RDP window.
0
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 

Author Comment

by:BFanguy
ID: 39835484
The domain admin users are also in a group called printers_hma and when they sign on, the see all the printers for Hma, just not the rest of the locations.  If I add the user directly to the security on the group, the printer shows up.  (all of the printers have local administrator), it's like TS3 (remote desktop server 3) is not honoring the Domain Administrators in the Administrator group.
0
 

Accepted Solution

by:
BFanguy earned 0 total points
ID: 39895087
This seems to have fixed itself.  my network admin made a statement that if you viewed the printers from "Devices and Printers" they showed up, but if you viewed them from a shortcut I have on allusers desktop called "Printers" they did not show up.

I just tested and they are showing up in both....
0
 

Author Closing Comment

by:BFanguy
ID: 39905886
problem went away.
0

Featured Post

Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
A procedure for exporting installed hotfix details of remote computers using powershell
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

837 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question