[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

Newly created domain user account added as local administrator cannot reboot server ?

Posted on 2015-01-07
9
Medium Priority
?
194 Views
Last Modified: 2015-01-08
Hi folks,

I have created one new domain user called HelpDesk_Admin in my AD console, I have also granted this AD account as the Local Administrators manually one by one in all of my Windows Server default builtin security group.

I can now login to the server with this DOMAIN\HelpDesk_Admin account, but somehow I cannot reboot or shutdown the server for Windows Update purpose ?

how can I grant the ability to reboot the server with this user ?

Thanks
0
Comment
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
9 Comments
 
LVL 7

Accepted Solution

by:
Deadman earned 400 total points
ID: 40537183
check Server default builtin security group add in GPO.

Start-->Run-->Type secpol.msc--->Local policies-->User rights assignment---> Look for Shut down the system--> Check your Server default builtin security group added.
0
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 40537225
ok, if there are hundreds of the Windows Servers, how can I automate this?
or do i need to logon manually to the server one by one again?
0
 
LVL 25

Assisted Solution

by:NVIT
NVIT earned 400 total points
ID: 40537307
I haven't tested this but... If you get a list of servers in a text file, you might be able to use psexec and ntrights. Maybe something like:
psexec @servers.txt -u domain\adminname -p password ntrights -U "DOMAIN\HelpDesk_Admin" +R SeShutdownPrivilege

Open in new window

You should first test it with a user to confirm that it works.
0
Cyber Threats to Small Businesses (Part 2)

The evolving cybersecurity landscape presents SMBs with a host of new threats to their clients, their data, and their bottom line. In part 2 of this blog series, learn three quick processes Webroot’s CISO, Gary Hayslip, recommends to help small businesses beat modern threats.

 
LVL 25

Assisted Solution

by:Sekar Chinnakannu
Sekar Chinnakannu earned 400 total points
ID: 40537308
you cna verify the server which you exactly you looking if not, you can configure the same on group policy
0
 
LVL 56

Assisted Solution

by:McKnife
McKnife earned 400 total points
ID: 40537381
Of course you can also solve this with GPOs, but first test if that really IS the problem. So take one server, open secpol.msc and look at that right assignment.
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 400 total points
ID: 40538279
Using GPO's would be much more efficient and also Domain GPO's override local policies by default. So if there are local policies that are preventing these tasks having them setup via GPO would override these server settings locally.

GPO is also better because when you add new servers in to the OU where this policy is applied your Group will be automatically added.

Will.
0
 
LVL 8

Author Closing Comment

by:Senior IT System Engineer
ID: 40539256
Thanks man !
0
 
LVL 25

Expert Comment

by:NVIT
ID: 40539276
@ITSystemEngineer. Thanks for the update.
Did you have a chance to try any of these solutions? Just curious which you decided to try and if it worked.
0
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 40539302
I tried the domain GPO for the security policies.

It is now working as expected.
0

Featured Post

Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A hard and fast method for reducing Active Directory Administrators members.
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question