Re: Joining Domain gives user limited rights

Tech-Archive recommends: Fix windows errors by optimizing your registry



Garry Bargsley wrote:
1.) Image the computer. 2.) Join computer to the Domain and reboot. 3.) Logon to the computer with a domain account pointed to the domain. 4.) The logon process takes about 25 minutes. Problem number one.

Check your DNS settings - DNS in client configuration should point to the DNS server which holds DNS data for your AD domain


5.) Once logged in, the user has limited rights, cannot even open the clock on the systray. 6.) The user we are using apart of the Domain Users group on the active directory. 7.) If I add the user to the local computers as an administrator then everything works fine. This is not acceptable because we cannot do that for 600+ computers. In my mind, that defeats the purpose of Active Directory if you ask me.

You can add all this users as local administrators with single point in GPO using restricted groups. Did this repair your trust in AD concept :)?


http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/TechRef/156780ef-eb36-4433-b3fe-1b1a15c18f6a.mspx
http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

--
Tomasz Onyszko
http://www.w2k.pl
.



Relevant Pages

  • Re: DNS running at 100%
    ... The reboot suggestions seems to have resolved this issue. ... >> The DNS server timed out attempting an Active Directory ... The event data contains ...
    (microsoft.public.win2000.dns)
  • ForestPrep failed
    ... Windows Active Directory schema update with error code ... Now when I reboot the server the following event is in the ... DNS event log: ... The DNS server has encountered a critical error from ...
    (microsoft.public.exchange.setup)
  • Re: KDC Event ID 7 and Wins startup errors.
    ... Scheduled reboot was done to ensure that no services/tasks are failing ... Event Type: Information ... Logon Failure: ... Caller User Name: $ ...
    (microsoft.public.windows.server.sbs)
  • Re: GC Question
    ... Just model how a DNS server would FIND ... new user accounts what tool should I use to make sure that i'm not ... other domains in the forest don't have Several folders that the top ... is able to logon on that domain including in the Domain Controller ...
    (microsoft.public.win2000.active_directory)
  • Re: slow logon
    ... Why is XP running slower while logon 1 ... XP clients can find the DNS server. ... Make sure no errors on logon scripts or GPO's that could be causing ... > We have a network with winxp pro-computers, ...
    (microsoft.public.windowsxp.network_web)