Re: Renamed local admin not enough rights

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



"LordFox" <rick.harderwijk@xxxxxxxxx> wrote in message
news:1145354832.132494.248330@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi,

Years ago, we decided to automatically have the local admin account
renamed. Recently we are having problems with this nice GP feature: the
renamed admin account no longer has local admin rights on the system
the account has been renamed on. This means that we can no longer
install certain drivers and software, such as a VPN client.

Does anyone have a clue as to what is going on?


We cannot be sure but we may offer some clues:

The "renamed" Administrator account is STILL
PRECISELY the same account (it has the same SID.)

When a computer joins a domain the Domain Administrators
group is (automatically) placed into the local Administators
group.

Anyone in the Domain Admins should be a local Admin, BUT
recognize that the membership of the Domain Admins (on the
domain) can be changed, as can the membership of the local
Admin group.

Check each of these -- some discrepancy in the above should
account for the problems.

Also, double check that the computer is STILL a member of
the domain AND able to AUTHENTICATE (usually problems
with Authentication are really DNS issues.)

--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]

Cheers,

Rick



.



Relevant Pages

  • Re: local admin account password
    ... What I think would be a better scheme is to set a very complex* random ... This eliminates the vulnerability created by weak admin passwords ... Do you think if someone wanted to break the local admin account they ...
    (Focus-Microsoft)
  • Re: Client Installation Issues: SMS 2.0 SP5
    ... Log on locally as LOCAL admin and install. ... Log on Locally as domain user who has LOCAL admin rights. ... The SMS Service account IS a domain admin ...
    (microsoft.public.sms.setup)
  • Re: Incoming E-Mail - cant create contact in OU
    ... central admin pool different than the web app. ... that account a little (if the web app is compromised or something, ... So I started with giving the app pool account domain admins permissions then ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: computers locked out of the domain?
    ... Admin so that some one could work at the station. ... in the active directory' users & computers I looked at the computer account ... down or the account etc but then when I log on to the local admin acc' I can ... use the remote desktop to connect to the server, no problems & when I take ...
    (microsoft.public.windows.server.networking)
  • Re: Domain admin login problem
    ... Several Login attempt wrote: ... Administrator Account. ... How can you logon to the DC as a Local Admin? ...
    (microsoft.public.windows.server.active_directory)