Click here to get back home

Administrator can't change security

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Administrator can't change security addoty 04-11-2006
Posted by addoty on April 11, 2006, 5:51 pm
Please log in for more thread options
I have two Windows Server 2003 R2 servers setup. One is the domain
controller. Both administrator accounts have the same password. On my
server that is not the domain controller, when I join the domain, the
administrator account cannot change any of the security settings for
any of the folders.

This happens if I set the administrator's login domain to the domain
controller or to the local computer. When I remove the second server
from the domain and return it to a workgroup, the administrator account
can make changes to the security settings.

This second server was upgraded from a Windows Server 2000 by inserting
the 2003 R2 CD. Why can I not make changes to any of the folder
security settings after the computer joins the domain?

Any help would be greatly appreciated.
AD


Posted by addoty on April 11, 2006, 6:07 pm
Please log in for more thread options
UPDATE:

I have access to update some folder security settings as administrator
but not others. When I right click on a folder and select the security
tab, some folders have the Add and Remove buttons disabled but other
folders I can change. If I click on the Advanced button it shows the
Administrators have "Full Control" for all folders.

Please help. Thanks,
AD


Posted by Steven L Umbach on April 11, 2006, 6:50 pm
Please log in for more thread options
If you mean that the user is logging onto the domain instead of local
computer you will need to add the user's "domain" account to the local
administrators group on the member server. It would not matter what password
is used as it is group membership that determines who is a local
administrator. You can use the command net localgroup administrators to see
what users/groups are in the local administrators group. If you change a
user's group membership make sure that the user logs of and logs on again to
update his security token with the change in group membership. Also if there
are DNS problems in the domain you will experience unexpected results when
domain users logon to member servers. The support tools dcdiag [domain
controllers only] and netdiag can help troubleshoot such along with checking
the logs via Event Viewer for errors/warnings such as userenv that can
indicate problems finding or contacting a domain controller. --- Steve

http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B291382 --- AD
DNS FAQ


>I have two Windows Server 2003 R2 servers setup. One is the domain
> controller. Both administrator accounts have the same password. On my
> server that is not the domain controller, when I join the domain, the
> administrator account cannot change any of the security settings for
> any of the folders.
>
> This happens if I set the administrator's login domain to the domain
> controller or to the local computer. When I remove the second server
> from the domain and return it to a workgroup, the administrator account
> can make changes to the security settings.
>
> This second server was upgraded from a Windows Server 2000 by inserting
> the 2003 R2 CD. Why can I not make changes to any of the folder
> security settings after the computer joins the domain?
>
> Any help would be greatly appreciated.
> AD
>



Posted by addoty on April 12, 2006, 10:20 am
Please log in for more thread options
Sorry, I'm a little confused and this is hard to explain. I'm in the
process of moving from Netware to Windows so please pardon my basic
questions.

I'm signing on as Administrator on a second Windows 2003 server that is
a member of the domain. It doesn't matter if I signon as Administrator
on the "local" domain on the second server or as Administrator of the
actual domain controller on the secon server, I cannot make any changes
to the security setting of certain folders. If I remove the second
server from the domain back to a workgroup, I can make the changes.

I have disabled all policies on the domain controller.

Your comment...

"If you mean that the user is logging onto the domain instead of local
computer you will need to add the user's "domain" account to the local
administrators group on the member server."

There is an Administrator account already in the Users folder in
"Active Directory Users and Computers" on the domain controller server.
It is a member of Administrators, Domain Admins, and a few more. How
can I add another Administrator account?

Thanks for any help,
AD


Posted by addoty on April 12, 2006, 10:26 am
Please log in for more thread options
UPDATE:

I misread your comment..."If you mean that the user is logging onto the
domain instead of local computer you will need to add the user's
"domain" account to the local administrators group on the member
server."

I check, the "Domain\Administrator" and "Domain\Domain Admins" are in
the Administrators group on the second Windows server. My question
still remains. Why can I not edit the security settings on a few
folders while I'm a member of the domain?

Thanks,
AD


Similar ThreadsPosted
Change Administrator SID September 21, 2008, 11:15 am
Safely change the Administrator accounts and names 2003 server July 11, 2007, 6:15 pm
Change security desc. on root folder January 31, 2007, 10:34 am
Changing the Administrator account username for security? June 15, 2005, 10:20 am
Domain Security Policy -> Access is denied for Administrator July 17, 2006, 7:04 am
Main Administrator account doesn't have Administrator groups right March 1, 2006, 2:35 pm
Is it possible to change computer sid on AD? February 8, 2006, 3:32 pm
change user in cmd March 3, 2006, 8:34 am
Registry change June 19, 2006, 11:30 am
Making a Change to SCW GPO December 19, 2006, 12:07 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap