?
Solved

How to add group to local administrators without removing the existing groups

Posted on 2014-12-18
4
Medium Priority
?
213 Views
Last Modified: 2014-12-24
Hello everybody,

I'm in the computer migration process using ADMT.

The migration will take place between the Forest A to Forest B.

I'm having a big problem to include a group domain B (which will be the new domain that will receive the accounts of computers) in the Local Administrator group of computers that will be migrated.

I've tried to make the process with the GPO Restricted Groups using the option This group is a member of and users and other existing groups in the Local Administrator group is removed when the GPO is applied.

I've tried using the GPO Local Users and Groups in Computers\Preferences Control Panel Settings and when I add a group domain B Administrators from the group created in domain A the Administrators group is simply removed from the group.

I'm doing something wrong?

There is another way to solve this problem?
0
Comment
Question by:lucianolima
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 18

Expert Comment

by:Emmanuel Adebayo
ID: 40506871
What level of authetication did you have between the two forest?

You will needd to Create a two-way, forest trust with forest-wide authentication.

regards
0
 
LVL 1

Author Comment

by:lucianolima
ID: 40506902
Hello Emmanuel,

I have Two-way trust with Forest-Wide Authentication.

Do you have any other ideas of what can be?
0
 

Expert Comment

by:Yusaf (Joe) Sneddon
ID: 40506911
Obviously if the trust is in place i would use a PowerShell script >> https://gallery.technet.microsoft.com/scriptcenter/Add-AD-UserGroup-to-Local-fe5e9239

Also the group policy preferences should work although never tried via that method across domains, so are you adding it under preferences and setting it to update the local administrators group? and its just removing it?
0
 
LVL 1

Accepted Solution

by:
lucianolima earned 0 total points
ID: 40509754
Hello everybody,

I solved the problem as follows:

I created a GPO and added a traditional .bat script in the Logon Script in User Configuration\Policies\Windows Settings\Scripts (Logon \ Logoff) the following command:

net localgroup "administrators" "domainname\domain admins" / add
0

Featured Post

What Is Blockchain Technology?

Blockchain is a technology that underpins the success of Bitcoin and other digital currencies, but it has uses far beyond finance. Learn how blockchain works and why it is proving disruptive to other areas of IT.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I was supporting a handful of Windows 2008 (non-R2) 2 node clusters with shared quorum disks. Some had SQL 2008 installed and some were just a vendor application that we supported. For the purposes of this article it doesn’t really matter which so w…
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question