Re: Domain Administrator have lost all rights

From: Fabrussio (Fabrussio_at_discussions.microsoft.com)
Date: 11/07/04


Date: Sat, 6 Nov 2004 16:12:02 -0800

is this the answer????
http://support.microsoft.com/kb/267553

Thanks?

"Enkidu" wrote:

>
> I'm pretty sure you can't remove the default domain controller's GPO.
> See if you can access that and replace the group as suggested.
>
> Try this KB article.
>
> http://support.microsoft.com/default.aspx?scid=kb;en-us;226243
>
> Cheers,
>
> Cliff
>
> On Sat, 6 Nov 2004 07:50:01 -0800, Fabrussio
> <Fabrussio@discussions.microsoft.com> wrote:
>
> >Thanks but I have deleted all GPO's and restricted groups and restarted the
> >server but the Domain Admin access is still restricted.
> >eg. I can't access any remote workstation c$ drive, I can't look at files
> >that have administrator Full control permissions, I can't access any
> >http://localhost web sites from the server.
> >
> >How can I get back control???
> >
> >
> >"ptwilliams" wrote:
> >
> >> Restricted groups replaces group membership - it doesn't merge (well, it
> >> can, but I can't remember the SP versions, and KBs). That's why it's called
> >> restricted groups - you restrict what members are in what groups. Just open
> >> up the GPO that you defined this in and add the domain admins group and any
> >> other missing groups at the GPO level.
> >>
> >> --
> >>
> >> Paul Williams
> >>
> >> http://www.msresource.net
> >> http://forums.msresource.net
> >>
> >>
> >> "Fabrussio" <Fabrussio@discussions.microsoft.com> wrote in message
> >> news:D133FFF0-2548-4EED-9C25-F5D53B93B488@microsoft.com...
> >> i have a single DC w2k sp4.
> >> I set up a restricted group in the AD to give workstation users - local
> >> admin access.
> >> I must have made a mistkae cos As soon as I set it up it stopped all my
> >> domain admin access and IUSR access from the server. I have completely
> >> removed all traces of the groups and related policy but the admin access
> >> never returns.
> >>
> >> Tried restarting server.
> >>
> >> what to do????? please help!!
> >>
> >>
> >>
>
>



Relevant Pages

  • Re: TS Configuration Permission
    ... This was a GPO at a higher level OU. ... > An about the Licensing Server: did you install permanent TS CALs ... There are no restricted groups in the domain. ... >> The licence server appears to be issuing temporary licences ...
    (microsoft.public.win2000.termserv.clients)
  • Re: Domain Administrator have lost all rights
    ... I'm pretty sure you can't remove the default domain controller's GPO. ... >server but the Domain Admin access is still restricted. ... >that have administrator Full control permissions, ...
    (microsoft.public.win2000.active_directory)
  • Re: How to define local groups in an AD computer policy?
    ... "Tomasz Onyszko" wrote: ... >> I have an active dir. with server 2003. ... >> groups in an AD GPO?" ... > The answer is not 44 but use Restricted groups in GPO to define ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain admin has lost administrative rights
    ... are a few ways to proceed to gain administrator access. ... computer account and proper connectivity to domain controllers you could use ... You could create an OU for your server that is a ... Restricted Groups to apply or reboot the server if possible which would be ...
    (microsoft.public.win2000.security)
  • Re: Adding accounts to group doesnt work
    ... Restricted groups with in a Group Policy allow to map membership: ... > I have strange situation.There is DC on Windows 2003 server. ... > administrator group of every workstation. ...
    (microsoft.public.windows.server.active_directory)