Re: Group Domain Admins cannot be found



Instead of adding the group to Domain Admins, which means that the members will also be able to administer the Active Directory, servers etc., consider adding the group to the local Administrators group on the workstations using Restricted Groups in seperate GPO linked to the OU that has the computers you want them to be able to install Kix on.

Restricted Groups are in Computer Configuration, Windows Settings, Security Settings. Use the "This group is a member of:" part of " Configure Membership for..." dialog box.

After Kix is installed, you could remove the user accounts from that group, or your Kix installation script could remove from the local Administrators group.

--
Bruce Sanderson
http://members.shaw.ca/bsanders

It is perfectly useless to know the right answer to the wrong question.



"SteveB" <SteveB.3pcm3b@xxxxxxxxxxxxx> wrote in message news:SteveB.3pcm3b@xxxxxxxxxxxxxxxx

I am trying to add a group (Global Security group) I have created in the
Users container to the Domain Admins group which is is in the same
container, but when I try to add it on the "Member of" tab, Check names
is unable to find the group Domain Admins. The group definitely exists.
Object types it is looking for are Groups or Built in security
principals. Location is BLAHBLAH.dom. I have tried changing the
Location all the way down the tree to the actual Users container and it
still cannot find the group.
I have also tried to add this in the opposite direction by choosing the
Domain Admins group and trying to add my group as a member but same
thing, cannot find the group.

Any ideas please??

The reason I am trying to do this is to use a group temporarily to be
added to local machine admins for an install using Kix.

The group has to be in the Domain Admins group to be able to add itself
to a local machine Administrators group. the script then installs the
software and then removes my group from the local administrators group.

I know it can work as I have just used the same procedures and scripts
on one of our other domains and succesfully installed Office 2007 across
the domain.

What could be the difference in this domain to the other one??

This Domain does use separate containers for the different departments
whereas the other domain was set up with everyone in the Users
container,but my group is in the standard Users container along with the
Domain Admins group, they just can't see each other!


--
SteveB
------------------------------------------------------------------------
SteveB's Profile: http://forums.techarena.in/members/61824.htm
View this thread: http://forums.techarena.in/active-directory/1144660.htm

http://forums.techarena.in


.



Relevant Pages

  • Re: How to change domain administrator to limited/restricted user?
    ... Depending on the number of users, computers, member servers and the rest of the infrastructure, I might be tempted to start over. ... If it's "a" domain administrator, then remove the user from the ... Are the individual users direct members of the Domain Admins group or members of a group added to the Domain Admins group. ... Check a workstation or two and see if the user is a member of the local workstation administrators group. ...
    (microsoft.public.windows.server.sbs)
  • Re: no Domain Admin rights to a Domain Server
    ... If the computer is still a member of the domain with proper DNS name ... the domain it needs to be joined to the domain again and the domain admins ... I can logon locally to the machine but the rights are that of a ... the server belongs to engineering and the person in charge ...
    (microsoft.public.win2000.security)
  • Re: Cant add domain administrator to directory users names
    ... > have been added to the local Administrators group automatically. ... machine is definitely a member of the domain though. ... > machine is a member of the domain then Domain Admins should already have ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Group Policy on a remote computer
    ... By default, members of Domain Admins are administrators on member computers, but not Enterprise Admins. ... The domain controller is Windows Server 2003 R2 SP2; the target computer is XP Professional SP2. ... The usual process is to create a Group Policy Object in the Domains Active Directory and link it to the OU with the target computer accounts or user accounts. ...
    (microsoft.public.windows.group_policy)
  • Re: Login Script
    ... helpdesk person) to not be a member of "Domain Admins", but to be able to be ... > (The user cannot add himself nor can the computer startup ... > We could build a Startup script that would do this IF ...
    (microsoft.public.win2000.active_directory)

Quantcast