Re: Domain administrator local admin on every machine




<g18c@xxxxxxxxxxx> wrote in message
news:1157289268.325199.94760@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
If you knocked yourself out then you have to put yourself back
into this group.

Thanks for the prompt reply. I've inherited a network of 20 pcs, and
for some reason even though ive added myself to domain admins group im
still locked out. Furthermore once i setup the domain admins i want to
disable all local accounts, or at least prevent login to local
accounts.

Is there anyway i can read-add domain admins to the local
administrators group? By default should i see them listed under the
comuter management -> users tab?

Cheers,

Chris


GUIS are great for users but I prefer to use Command Line
commands - they are often much faster. I gave you most of
the command in my previous note. All you need to do is to
expand it for your current requirement.

You should not have any local accounts other than "Administrator"
plus a backup admin account for times of trouble. Simply remove
the other accounts (but leave the system accounts in place) - this
will prevent people from logging on locally. And change the
password too while you're at it!

net user xxx /del
net user Administrator SomeStrongPassword
net user BackupAdmin SomeStrongPassword /add
net localgroup Administrators "Domain Admins" BackupAdmin /add


.



Relevant Pages

  • Re: Settle a Administrators dispute
    ... if a user is in Administrators or Domain Admins they can give themselves as much rights as they want in the forest. ... Our disagreeable admin says that if a Global Group is put into the Administrators Local Group on the DC but not in the Domain Admins Global Group, the users of the Global Group do not have the same permissions as the Administrator account -- particularly to add/modify/delete user/computer/group accounts in AD. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain User Account / Log On Problem
    ... Administrators, Domain Admins, Enterprise Admins etc. ... > I'd changed Domain Controller Security Policy-Allow log on locally and i ... applied and allow other user accounts to log on. ...
    (microsoft.public.windows.server.active_directory)
  • Administrative user accounts no longer has admin privs?
    ... The accounts I use for administrative tasks has ... a member of Domain Admins, and Domain Admins is a member ... Administrators group I'm met with the same message. ...
    (microsoft.public.win2000.security)
  • Re: Membership in Admin groups resets Send As permissions - Blackberry
    ... those protected groups having Send As rights. ... Why would Microsoft put a change this drastic ... it so that Administrators CANNOT use Blackberry's. ... Also, this basically forces any admin to have 2 accounts, otherwise they ...
    (microsoft.public.exchange.admin)
  • Re: Membership in Admin groups resets Send As permissions - Blackberry
    ... those protected groups having Send As rights. ... Why would Microsoft put a change this drastic ... it so that Administrators CANNOT use Blackberry's. ... Also, this basically forces any admin to have 2 accounts, otherwise they ...
    (microsoft.public.exchange.admin)