Re: No user accounts that are Enterpise Admins can connect to othe



Ran the whoami against the user while logged onto a DC. The user is a member
of the Enterprise Admin group and the sid is there.

"Jorge de Almeida Pinto [MVP - DS]" wrote:

enterprise admins is not a member of local servers administrators group,
only the domain admins group is

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"Mike B." <MikeB@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C684A5F4-C7AC-420B-9FD1-4DE148D35795@xxxxxxxxxxxxxxxx
I will check for this in the token.
Basically it is from one of the child domains connecting to member servers
in other child domains. Able to UNC to the admin share to domain
controllers in other domains, just member servers.

Thanks!

"Jorge de Almeida Pinto [MVP - DS]" wrote:

are you sure the enterprise admins sid is in the access token? (use
WHOAMI
/GROUPS on a w2k3 server or use SECTOK from joeware.net)
are the enterprise admins member of the local domain administrators
group?

and even most important....WHICH ADMIN$? a DC? a member server? a client?
and in which domain?

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no
rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"Mike B." <MikeB@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:54A2A7A3-99AD-4568-B19F-6DCDBADEA1AB@xxxxxxxxxxxxxxxx
Here is a strange one.
Windows 2003 Native Forest.
I have one root domain and four child domains.
In one Child domain, the members of the Child domain's admin group are
members of Enterprise Admins. When these user and the builtin
administrator
account try to UNC to the admin share "c$", these users are promted
with a
Windows Logon window. Even if they input their username and password
it
still prompts them.

Anyone see anything like this before?






.



Relevant Pages

  • Re: Loginscript is lacking credentials.........
    ... Create the gpo in the ou where the Computers reside, ... right click on restricted groups and select new group (For the local ... machine is a member of the local administrators group him/herself, ... I was under the impressions that all GPO's ran with top admin credentials. ...
    (microsoft.public.windows.server.active_directory)
  • Re: need local admin rights with domain login
    ... To add a user into the local machine, you must be the member of the Power ... This newsgroup only focuses on SBS technical issues. ... |> not run unless the user has admin rights. ...
    (microsoft.public.windows.server.sbs)
  • Re: Security without signon
    ... Admins has permissions on the back-end tables? ... then theoretically the Admin user coming in through ... SystemMDW (who is a member of the Admins group in SystemMDW) in your scenario ... owner of these objects is my SuperUser, so I don't think that's it. ...
    (microsoft.public.access.security)
  • Re: Giving local Admin rights to AD 2003 Domain Admin users
    ... Once I connect the machine to the domain it took the old member name and I used the existing domain account to logged in. ... When I logged on to other machines using the same account I could do admin tasks, But not when I looged in to this machine. ... BUT the part I dont understand is in other machines this account can do admin tasks with out addin the account as a member of local admin. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Please help with folder permissions
    ... I am not intending to encourage use of admin by all of the local logins, ... All the domain users are a member of the local administrators group. ... The user becomes the owner not the local admin group. ...
    (microsoft.public.win2000.security)

Quantcast