Re: Domain User Privileges on Client Computer

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hello Genesis,

If you check the "Members" and "Member of" tab on the groups, you can exactly see to what groups they belong or where they are member of. So if they are members of enterprise admins they have all rights. Because "Enterprise admins" are member of "Administrators" and "Administrators" have local admin rights in a domain by default.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Thank you for the reply Meinolf Weber.

I checked the Active Directory services. The Domain Users is linked to
a Domain Group. I looked at the Group Policy Management, the Domain
Group has permissions: Link GPOs. Under the Groups and Users with
permission on the Domain Group is Enterprise Admins: Inherited = yes;
Status = Applies to this container and all child containers.

Domain Users -> Domain Group -> GPM -> Permission -> Link GPOs ->
Groups and Users w/ Permission for Domain Group -> enterprise Admins
-> Inherited: YES -> Setting -> Applies to this container and all
child containers

Not sure if what I just said is clear to you or fuzzy since I am a
novice-backup on this.

Is the structure causing the domain users to have administrator
privileges on client computers?

Thanks again.

"Meinolf Weber" wrote:

Hello Genesis,

If they are not added to the local administrators group with a
specified group or the account itself, basically it can not be. Even
if you use a GPO with restricted groups they should be listed in the
local admins group. Did you check Active directory builtin groups
like enterprise admins etc.? Are the domain user accounts you are
taking about addded there?

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
Hello Everyone!
I don't know if I am posting in a correct category, so please tell
me.
here is the problem: All domain user accounts suddenly have
administrator privileges on the client computers. I checked the
client
computers if the domain users are set up as administrators but they
are not. Checked the domain users setting found everything is ok. If
I
connect a new client computer to the domain and a domain user
logged-in the privilege is not that of the administrator.
Am I missing something here? Any idea?

Thank you.



.



Relevant Pages

  • Domain users = local administrator
    ... I thought it was a good solution to set all the domain users to be local ... administrators by using the KB320065. ... users are also administrators of member servers... ... SMS) without giving them administrative rights on member server? ...
    (microsoft.public.win2000.security)
  • Re: Connecting to a domain controller
    ... > without the user being a member of Administrators. ... To allow Domain Users group to log on, ...
    (microsoft.public.win2000.termserv.clients)
  • Re: making all users an admin of local machine by default
    ... Make "Domain Users" a member of ... the local PC "Administrators" group ... ... > that ever logs onto any Windows 2000 workstation on my network is ...
    (microsoft.public.win2000.security)
  • Re: making all users an admin of local machine by default
    ... Make "Domain Users" a member of ... the local PC "Administrators" group ... ... > that ever logs onto any Windows 2000 workstation on my network is ...
    (microsoft.public.win2000.setup)
  • Local Admin of sub domains
    ... I have created a user which a member of the "Administrators" group on master.local, and I want to also give the user local admin rights on servant.master.local. ... However if I use the users and computers control on master.local, I am unable to make this user a member of the Administrators@servant group ?? ... I have also tried making this user a member of Enterprise Admins, but then fail to make Enterprise Admins a member of Administrators@servant. ...
    (microsoft.public.windows.group_policy)