We help IT Professionals succeed at work.

Help with troubleshooting Microsoft System Account removing users from Domain Admins Group

110 Views
Last Modified: 2019-02-26
I have an issue where a task/job run by the NT AUTHORITY\SYSTEM removes users from the Domain Admins. I am unable to find out if this is a task, GPO, or what is causing one  our domain controllers to execute this. I then have to go and add all of our domains admins back in the group about 1 or 2 times a day. Is there a powershell command, utility, or any recommendation that will display what time a task or GPO runs to help troubleshoot this process? I need help figuring out what is causing the system account 'NT Authority\System' to remove the users from the domain admins.
Comment
Watch Question

ChrisLead Infrastructure Architect
CERTIFIED EXPERT

Commented:
If you have auditing on for AD then you will be able to pin point the time and the source of the change

saving me having to type it out this page gives you details on the event auditng that needs to be configured and the event ID's you need to look for

https://www.lepide.com/how-to/track-and-audit-active-directory-group-membership-changes.html

you can cross check that with the Group Policy log which is one of the granular logs to see if there is a time stamp that correlates and also what GPO it was that was doing a backgroun refresh.
Or the system log that should confirm a scheudled task running
RobertSystem Admin
CERTIFIED EXPERT

Commented:
This could be due to protected group.
In the past I had a group that was a member of a protected group and that caused windows to remove the members.

https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-c--protected-accounts-and-groups-in-active-directory

Author

Commented:
Thanks and I am looking at the logs and I have read about protected group and restricted groups. Still no luck...
CERTIFIED EXPERT
Top Expert 2012

Commented:
please post output of
gpresult /h c:\gpreport.html

Open in new window

Author

Commented:
Life1430 is there something specific I can look for and I appreciate the help but I cant post the gp policy due to company policy
CERTIFIED EXPERT
Top Expert 2012

Commented:
Nothing specific as such..was expecting any clue if we could find from it
Commented:
This one is on us!
(Get your first solution completely free - no credit card required)
UNLOCK SOLUTION

Gain unlimited access to on-demand training courses with an Experts Exchange subscription.

Get Access
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Empower Your Career
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE

Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Unlock the solution to this question.
Join our community and discover your potential

Experts Exchange is the only place where you can interact directly with leading experts in the technology field. Become a member today and access the collective knowledge of thousands of technology experts.

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.