Administrative user accounts no longer has admin privs?

From: Michael Howard (anonymous_at_discussions.microsoft.com)
Date: 11/26/03


Date: Tue, 25 Nov 2003 17:20:39 -0800

The accounts I use for administrative tasks has
apparently lost its administrative status.

When I attempt to install software on a domain account
(including DC's) I'm told that the account does not have
privileges and to log on with one which does.

The account has not had group membership changed. It is
a member of Domain Admins, and Domain Admins is a member
of the local Administrators group (on machines other than
DCs).

Even if I explicity add the accounts to the
Administrators group I'm met with the same message.

This happens on two separate accounts that I keep for
admin tasks--one simply a copy of the other (for testing
purposes).

If I create a new user, assign them to Domain Admins, all
is fine.

This happens on XP clients as well as 2k clients.



Relevant Pages

  • How to add a local group to the local administrators group with GP
    ... all the local administrators accounts specific for each server. ... to add a new member to the LOCAL Administrators built-in group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain administrator local admin on every machine
    ... Furthermore once i setup the domain admins i want to ... disable all local accounts, or at least prevent login to local ... net user Administrator SomeStrongPassword ... net localgroup Administrators "Domain Admins" BackupAdmin /add ...
    (microsoft.public.windows.server.general)
  • Re: Sub Domain Admin Accounts
    ... because it is a member of the Enterprise administrators universal group. ... Other members of the child domain admins group would not have this ability ... >> no technical reason why an admin accounts in one domain need to access ...
    (microsoft.public.windows.server.general)
  • Re: Settle a Administrators dispute
    ... if a user is in Administrators or Domain Admins they can give themselves as much rights as they want in the forest. ... Our disagreeable admin says that if a Global Group is put into the Administrators Local Group on the DC but not in the Domain Admins Global Group, the users of the Global Group do not have the same permissions as the Administrator account -- particularly to add/modify/delete user/computer/group accounts in AD. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Membership in Admin groups resets Send As permissions - Blackberry
    ... those protected groups having Send As rights. ... Why would Microsoft put a change this drastic ... it so that Administrators CANNOT use Blackberry's. ... Also, this basically forces any admin to have 2 accounts, otherwise they ...
    (microsoft.public.exchange.admin)