Re: No user accounts that are Enterpise Admins can connect to othe



enterprise admins is not a member of local servers administrators group,
only the domain admins group is

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"Mike B." <MikeB@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C684A5F4-C7AC-420B-9FD1-4DE148D35795@xxxxxxxxxxxxxxxx
I will check for this in the token.
Basically it is from one of the child domains connecting to member servers
in other child domains. Able to UNC to the admin share to domain
controllers in other domains, just member servers.

Thanks!

"Jorge de Almeida Pinto [MVP - DS]" wrote:

are you sure the enterprise admins sid is in the access token? (use
WHOAMI
/GROUPS on a w2k3 server or use SECTOK from joeware.net)
are the enterprise admins member of the local domain administrators
group?

and even most important....WHICH ADMIN$? a DC? a member server? a client?
and in which domain?

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no
rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"Mike B." <MikeB@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:54A2A7A3-99AD-4568-B19F-6DCDBADEA1AB@xxxxxxxxxxxxxxxx
Here is a strange one.
Windows 2003 Native Forest.
I have one root domain and four child domains.
In one Child domain, the members of the Child domain's admin group are
members of Enterprise Admins. When these user and the builtin
administrator
account try to UNC to the admin share "c$", these users are promted
with a
Windows Logon window. Even if they input their username and password
it
still prompts them.

Anyone see anything like this before?





.



Relevant Pages

  • Re: New AD installation issue
    ... Then a second server was added to the domain. ... (I am a member of the Administrators ... Membership of the Administrators group in the domain gives you admin access ... Membership of the Domain Admins group grants you admin privileges to the ...
    (microsoft.public.windows.server.active_directory)
  • RE: Installing Software and Permissions
    ... MCSE, CCEA, Microsoft MVP - Terminal Server ... member of Domain Admins... ... until user1 was added directly to the TS Servers Local Admins ... Server - Administrators 6) All in all the Local Administrators ...
    (microsoft.public.windows.terminal_services)
  • Re: I shot my foot off almost and the Admin cant log into the server locally
    ... server. ... Keep a backup administrator id around. ... > By default the Administrator should be a member of these groups: ... > Administrators, Domain Admins, Domain Users, Enterprise Admins, Group ...
    (microsoft.public.windows.server.sbs)
  • Re: Adprep /Forestprep Error
    ... member of domain admins, enterprise admins, schema admins. ... > also be a member of the Schema Admins group to make schema changes at all. ... > the same issues with ADPREP. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADPREP /forestprep And R2
    ... That error generally means that in fact you're not member of the Shema ... Server 2003 R2 and the DFS component that comes with it. ... Enterprise Admins Group and Schema Admins Group ...
    (microsoft.public.windows.server.active_directory)