Re: cannot add local user to local group



Hello Dkp,

You can control the Local Administrators group with the Restricted Groups Policy. Only accounts, groups in this group will have the local administrator rights. Even the Administrator has to be added to the group to keep his local admin right.

http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.

On Oct 17, 9:35 pm, Meinolf Weber <meiweb(nospam)@gmx.de> wrote:

Hello coder_2007,

Talk to your SYSADMIN. He can give you more infos about the domain
and maybe he is controlling the local administrators group. Then you
can't do it because he can kick outb the local admin "test".

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers
no rights.
Hi Meinolf,

Thanks for responding. The local user account is "test" and a
domain name is test, I don't know if there's a user on domain called
test, I doubt if there was one it would cause problems.

Thanks.

"Meinolf Weber" wrote:

Hello coder_2007,

Just to clarify. One local user account "test" and one domain user
"test"
? You add "test" from domain or local, to the local group
"Administrators" ?
The point is, you have two totally different useraccounts with the
same name.
Every user object, doesn't matter if domain account or local, has a
specific
unique Security identifier (SID). So you have to check if the
account
is
member of the domain or the local user account.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties,
and
confers
no rights.
Hi,

I have a similar issue, I create a local user with a user name the
same as our domain, however once I add that user to Administrators
group, the user doesn't appear in Administrators group and the
"Member of" tab is empty. When I attempt to add this local user
to Administrator group again, I get error message that the user is
already a member of group "Administrators" but I can't see the
user in that group. Is there some sort of conflict of a local
user with domain?

Thanks.

"Meinolf Weber" wrote:

Hello Jan,

To come more clear please post the complete domaine name. Also in
a domain you normally work not with local accounts, you work with
domain user accounts, please give some more infos why you will
use local accounts and also why they have to be local admins.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties,
and
confers
no rights.
if we try to add the local computer account 'ABC' to the local
administrators group on a Windows XP PC we receive the message "
'ABC' is already a member of group 'Administrators', which is
not the case as the user has no administrative rights. on
Windows 2000 we do not receive a similar message but the user is
not added to the appropriate group. if we check the group
memberships of user 'ABC' there are no entries.

This happens on every computer that is a member of our active
directory. i assume that this might be a problem as our active
directory netbios domain name is also 'ABC'.

Any ideas how to fix this?

hi,

Looks like its a bug on windows side. It is not allowing to add a user
to administrator group with the name same as it netbios domain name.
There is no such settings present on the Domain controller side to
avoid this.



.



Relevant Pages

  • Re: Windows Service - Event Log
    ... I didn't say the Administrator account. ... Administrators group on the local machine." ... I didn't advocate using a member of the Administrator's group; ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Rid AD of Circular Group Membership
    ... and have use on members if it is used there. ... Administrators group is still intact), nor do they have empowerments over ... Admins is being used for by the 30+ can be delegated I(ex. ... The quess is each has an account and uses it, ...
    (microsoft.public.windows.group_policy)
  • Re: Local admin domain user
    ... Do not take this as an endorsement of your need to give users local admin ... That said, on the client machine, add the users domain account to the local ... administrators group, click "ADD", select the domain where the account ... > I need the users to have admin rights to their workstation ...
    (microsoft.public.win2000.security)
  • Re: Need Administrator authority
    ... I'm a member of the administrators group but that is apparently not enough. ... If you're logging onto the machine as garydean and the account is an admin/user account, then add user/garydean with full rights to match Administrators, because in some cases, Vista and UAC look at the combined rights of the two accounts, if that *user* account is missing or doesn't match the rights of Administrator's, then access denied or you don't have the privileges. ...
    (microsoft.public.windows.vista.general)
  • Re: Domain Lockout
    ... > No regular user who is not a member of the local administrators group ...
    (microsoft.public.windowsxp.security_admin)