Built-In Domain Level Groups dont have permissions on domain they should on 2012

Hello,
First this is a brand new domain environment with everything running server 2012 datacenter edition.
Second I've never seen anything like the following occur in a domain environment. What I had is what appears to be a bad 2012 AD structure however so far all AD tests come back good. The problem is the built-in domain level groups do NOT offer any level
of access that they should. For example if I add a user in the administrators group, they don't have any permissions that group is supposed to have. THe same with every other builtin, backup operators, server operators, account operators and on and on. The
only way a user gets that level of access is if I add them into the domain admins group. As you can imagine this is crazy and not a solution for my help desk crew. (having them all be domain admins that is) So while I could very well use delegation, I need
to find out why my builtin groups don't function as they should.  Anyone have any ideas on what to check or where to look?  I'm at the point of opening a case with Microsoft on this.
Thanks in advance

Because those builtin groups AREN'T domain level groups in the way you're thinking. The Administrators group on the server gives users administrator permissions on the server, but that doesn't mean permissions on the entire domain.
If you look in the user list in ADUC you'll see that while Domain Admins are a Global security group, Administrators is only a local group, eg local to the server (or more accurately since they no longer have local details, to domain controllers), so doesn't
grant permissions to anything outside of the domain controller. On all non DC's the machines have their own local administrators group which is independent of the domain one, and can have different memberships.
So if you only need a user to have permissions to the DC then administrators is fine, but if you need them to have access to the entire network, eg other servers and workstations, then they need to be members of domain admins. If you only want them
to have limited permissions then you need to grant those permissions either via a global/universal group, or by adding them to the relevant local group on each machine they need access to.

Similar Messages

  • Having troubles running iTunes! I downloaded iTunes just fine, but when I try to open it, it tells me iTunes is in a locked disk or I dont have permissions to write to this folder. Please help!

    Having troubles running iTunes! I downloaded iTunes just fine, but when I try to open it, it tells me iTunes is in a locked disk or I dont have permissions to write to this folder. Please help! I purchased an iPod for my son and wanted to put music on it.

    Hello there KRerssig,
    I was looking through our resources and found an article with information regarding that error message. The article is called iTunes for Windows XP: "Disk is locked" or "iTunes folder cannot be found" when installing or opening iTunes found here: http://support.apple.com/kb/HT1866.
    Here is the text but the article contains images for a visual reference:
    Verify the location of your Windows XP My Music folder. The default location for this folder is
    C:\Documents and Settings\username\My Documents\My Music
    If you do not have this folder at the default location and have not moved it to another location, consider creating one inside your My Documents folder.
    Download and install Tweak UI from the Microsoft PowerToys website athttp://www.microsoft.com/windowsxp/downloads/powertoys/xppowertoys.mspx
    Note: This utility is for Windows XP only. Please review the system requirements before installing.
    Once you have installed Tweak UI, open it from the Start menu.
    In the column on the left, click on the plus symbol next to My Computer and select Special Folders.
    In the right pane under Special Folders, choose My Music from the Folder pop-up menu.
    Click the Change Location button. You may see a warning message appear with precautions for changing this setting; after reviewing the message, click Yes.
    In the resulting window, browse for the My Music folder as described in step 1, and click OK.
    Reinstall or open iTunes.
    If these steps do not resolve the issue, the settings for the current user may be corrupted, which could cause iTunes not to install or open. You may have to install and open iTunes in a different Windows user account.
    All the best,
    Sterling

  • HT1212 My iphone is saying " iphone is disabled" and i dont have FindMyIphone set up, what should i do.

    My iphone is saying " iphone is disabled" and i dont have FindMyIphone set up, what should i do

    If you have forgotten the passcode for the lock screen, connect in recovery mode to restore:
    iOS: Unable to update or restore
    You'll get the option to set up a new code during this process.

  • I just bought a 25$ Gift card for itunes and i forgot my secuirty questions and i dont have a rescue email what should i do? Plz help

    i just bought a 25$ Gift card for itunes and i forgot my secuirty questions and i dont have a rescue email what should i do? Plz help

    There is another option if you still know your ID's password.  Call Apple directly and ask for the Account Security department.  They will need to verify that you are the account holder, but they should be able to force a reset for your security questions if they do so.
    For security questions they are required to get a support pin for the account from you.  You can get one by going to appleid.apple.com (no www in front) and signing in using the Manage Apple ID button.  The support pin is in the bottom-left corner of the password and security section, but don't generate it until they ask you to.
    You will still need to verify one other piece of information with you once this is done.  At this time, there is no other way to reset the security questions without having added a rescue email before losing them.  An Apple Retail Store would actually need to call in for you too, so don't worry about not having one.
    Good luck!

  • The folder cant be opened because you dont have permissions

    This is referring to my attempt to access my external 1TB LAcie Drive
    The only thing i can think of is that i have recently renamed the Drive on my dektop
    It holds only data and no apps
    Welcome advice or pointers to the resolution of problem

    Update
    Please ignore - me thinking i know more than i do
    i simply shut down checked cables and it worked upon restart
    a tip that i recently discovered and as a very familiar mac os user was surprised i didnt know and thus maybe others also forgot or didnt notice
    - Restart is different to ShutDown
    When you want a full system reboot you must shutdown not just restart
    Cheers

  • HT4813 How to I edit this file, it says its locked and I dont have permissions: default_default.conf.default.

    I need to add index.cfm to my default document tree.  I finally found where to change it in Lion Server.  When I try to edit the file, it wont let me.  Any way to edit the file?
    default_default.conf.default.

    Sorry, are you sure that you have typed the correct password for the admin (after sudo -s)?
    hostname:sites_disabled pyro$ sudo -s
    Password:
    bash-3.2# pwd
    /private/etc/apache2/sites_disabled
    bash-3.2# ls -lha
    total 0
    drwxr-xr-x   5 root  wheel   170B Jan  3 14:56 .
    drwxr-xr-x  34 root  wheel   1.1K May  2 11:57 ..
    -rw-r--r--   1 root  wheel   697B Jan  3 10:36 0000_default_default.conf
    -rw-r--r--   1 root  wheel   697B Jan  3 10:36 default_default.conf
    -r--r--r--   1 root  wheel   697B Jan  3 10:36 default_default.conf.default
    bash-3.2# chmod 644 default_default.conf.default
    bash-3.2# ls -lha
    total 0
    drwxr-xr-x   5 root  wheel   170B Jan  3 14:56 .
    drwxr-xr-x  34 root  wheel   1.1K May  2 11:57 ..
    -rw-r--r--   1 root  wheel   697B Jan  3 10:36 0000_default_default.conf
    -rw-r--r--   1 root  wheel   697B Jan  3 10:36 default_default.conf
    -rw-r--r--   1 root  wheel   697B Jan  3 10:36 default_default.conf.default
    bash-3.2# chmod 444 default_default.conf.default
    bash-3.2# ls -lha
    total 0
    drwxr-xr-x   5 root  wheel   170B Jan  3 14:56 .
    drwxr-xr-x  34 root  wheel   1.1K May  2 11:57 ..
    -rw-r--r--   1 root  wheel   697B Jan  3 10:36 0000_default_default.conf
    -rw-r--r--   1 root  wheel   697B Jan  3 10:36 default_default.conf
    -r--r--r--   1 root  wheel   697B Jan  3 10:36 default_default.conf.default

  • HT1212 my ipad is disabled and says connect to itunest. i dont  have a computer so what should i do

    My ipad mini is disable and says to connect to itunes. It wont connect because i have a passcode but cant put that passcode it cause its disable

    1. Beg, borrow or steal a computer.
    2. Get help from your nearest Apple Store.

  • I  bought used ipad from someone and i dont have eny connection way to hem and i dont have his apple accont , what should i do ? i want help please.

    How can i remove apple accont in used ipad?

    If the iPad has Activation Lock - that is, it's asking for the previous owner's Apple ID and password to activate the device - then you will need that information, or you'll need to get the previous owner to remove the device from his/her iCloud account:
    http://support.apple.com/kb/PH2702
    If you can't reach the previous owner or he/she is unwilling to cooperate, then the device is unusable by you. Return the iPad for a refund if you can.
    Regards.

  • Just dropped and cracked my ipod screen. I dont have a warranty. will they replace it?

    will apple replace my cracked ipod screen without a warranty?

    Hi,
    If you cracked you screen, it is NOT covered but the warranty. Here is the site by Apple about the price to fix it.
    http://www.apple.com/support/ipod/service/prices/#us
    xxmitchxx90

  • I went where i buy my iphone cuz i dont have any soynd n they say its water damage

    I was talkig on the phone when it was raining a bit n after i got home i got no more soud on my iphone n i went where i buy my iphone they say its water damage how

    Asked and answered:
    Question:
    "they say its water damage how"
    Answer:
    "I was talkig on the phone when it was raining"

  • I deleted my  media db3 file but I still dont have fx and filters what should I do?

    Barbara told me since I could not get my fx and filters to appear when I click them in the full edit mode I should delete my media db3 file and let it repopulate itself after it launches.  It didn't, what should do next?  I also deleted that file from my trash and it is not in my finder file any more.
    fred

    Barbara,
    That was the problem.  Once I changed the read write status of the user acct and then deleted the media db3 file in that user acct and relaunched the program it repopulated the effects and filters pallate.
    Thanks so much for ending this frustration. 
    Like I said I purchased your book on the missing manual for PSE for Mac and I am slowly absorbing its content.  Do you know of any helps that I could use to see some of your teachings in a live presentation somewhere on the web?
    Fred

  • I forgot my security questions and dont have a rescue email what should i do?

    i really do need help with this please

    You can also call your country number from http://support.apple.com/kb/HE57 and ask to speak with Account Security.

  • Which unity accts can I take off "domain admin" group after install

    Hi
    Unity 5.X in UM mode - Which unity accts can I take off "domain admin" group after install (ie unityinstall, unityadmin, UnityMsgStoreSvc, UnityDirSVC etc..)
    and if I do so, what is the impact or if I want to upgrade in the future?
    Thanks

    UnityInstall should be the most powerful account and is the only account that should be added to the Domain Admins group by the Permissions Wizard.  This is definitely true for Exchange 200, 2003, and 2007.  I've not dealt with a lot of customers on 2010 yet so this could have changed; however, I doubt it.  You can verify what I'm telling you here:
    http://www.ciscounitytools.com/Applications/Unity/PermissionsWizard/Unity403_411/Help/PWHelpPermissionsSet_ENU.htm
    This link will tell you what permissions and group memberships are set at a high level for all the Unity service accounts.
    To clarify what Jonathan said, by "downgrade" the UnityInstall account - the rule of thumb is this:
    Cisco supports that you DISABLE the UnityInstall account, if desired, after an installation.  This account should only be used during installation activities.  However, DO NOT DELETE the account in AD.  So, again - disabling the account is OK.
    Hailey
    Please rate helpful posts!

  • Don't have permissions to data drives after replacing system drive

    In my 10.4 Mac Pro, the hard drive with the OS died.  I have two more hard drives in there that I store all my data on, those are fine.  I bought a new drive, reloaded OSX, created a administrator account during setup, but now I don't appear to have access to my data drives.  I did a command+i and tried to reset it to my administrator account and group having read & write, and everyone else having read & write (as other people use this computer too, we all share the data drives so the permissions need to be wide open for everyone) but it says I dont have permissions to do it.
    Anyone know how i can blow open the permissions on those two data drives?

    Thanks - I did go there but couldn't find my specific issue addressed.
    In any event - I've since discovered that the two HD in question (although I use them on a daily basis with no problem) both had "Ignore ownership on this volume" checked in the Info window. The two I COULD access (via Time Machine) did not.
    So I unchecked that box on the 2 problem drives and, when I went back into TM, was able at least to select each hard drive with no error messages.
    Unfortunately, execept for the "Today" state, TM would NOT go back in time to show files on either of the two  previously-locked drives for all of the yesterdays that it backed them up.
    Unless I can figure out how to access Time Machine as "System" I think all those archived files are lost to me on the two drives.

  • Can anybody help me i just got my iphone 6 and i dont have passbook on my setting

    can anybody help me i just got my iphone 6 and i dont have passbook on my setting

    There should be a setting for "Passbook and & Apple Pay" in the group of three that also includes "iCloud" and "iTunes and App Store"

Maybe you are looking for

  • Load Balance https based on url

    I am trying to configure ACE 4710 to load balance base on the URL, If it matches the specific URL ( /456/ ), the traffic will be sent to server farm 456 else the traffic will be sent to server farm 123. I attached an image of the topology. Ace Config

  • Convert_otf in unicode system

    Hello, we have switched a CRM4.0 system from non-unicode to unicode. In this context we became two problems with the result of the function module 'CONVERT_OTF'. We call the function Module following:   call function 'CONVERT_OTF'    exporting      f

  • Does anyone 'not' have an afflicted superdrive?

    Everyone is talking about how the superdrives don't work, but is there anyone out there who has read this that does have one that works? Just thought it would help us all out, getting a perspective on how many work... Thanks!

  • Need help converting PSD to EPS using Illustrator

    Hello everyone! I'm trying to convert .psd files into an .eps using a batch process in Illustrator. I know you can save a .psd into an .eps in Photoshop, but it ends up flattening most of the image and I need all text to remain editable in Illustrato

  • SAP data update to Micorsoft Outlook via Outlook intergration

    Hi All, Could we create an activity in SAP Business One and have it update to Microsoft Outlook Calendar/Task/Note by using Outlook intergration?  Also, could we update the SAP BP info to Microsoft Outlook Contacts?  Thanks.