Re: Local user privileges



Hi Mark,

Thank for your help. I will try to describe the situation...

On AD the user is member of "domain users". This is fine.

Then I go to the local machine and look at the users from control panel. I
can see that the user login into the domain has administrator privileges. I
can change the privileges to user from the control panel but then the
account doesn't work. So my only option is to set the local account to
administrator for the account to work.

Is it possible that this problems happens becouse the user account has a
roaming profile?

Regards,
Angel.

> This is not the default behavior.
>
> If you look at the user object in AD, which security groups
> is the user member of?
>
> Lock in as administrator and remove the dom-user from the local
> administrator group. Lock in as user, if he is admin again, then
> there is something that takes efect on the default behavior.
> In a GPO you can manipulate this via restricted groups.
> You mus configure this manually to change the default behavior,
> thats why I think, taht there is no entry.


.



Relevant Pages

  • Re: Login as local admin
    ... So if i basically ensure that my domain administrator account is a member of ... the schema admins, and enterprise admins, and login using these credentials, ... The article does not reference "local" administrator (as far as I ... If you choose to use an account other than the built-in administrator ...
    (microsoft.public.windows.server.sbs)
  • Re: Windows Service - Event Log
    ... I didn't say the Administrator account. ... Administrators group on the local machine." ... I didn't advocate using a member of the Administrator's group; ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Setting a password on an AD account...
    ... I assume it's running in a restricted account right? ... You don't use SSL to bind, and as this runs from a server which is not a domain member (a ... this one fails when the current user is not an administrator on the DC. ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Send As problem
    ... I work for EDS in the Wells Fargo Building. ... >> Yes I would test this with another account, also check to see if for ... >> reason the Domain Users group happens to be a member of one of the ...
    (microsoft.public.exchange.admin)
  • Re: can a sysadmin change the win2000 domain admin password ?
    ... Pretty obviously if the person is a member of the Builtin\Administrator ... could change the password of the OS administrator account ... ... a person who is a member of the SysAdmin role can ...
    (microsoft.public.sqlserver.security)