Users added to the local Administrators group accounts

Hello

In our area (win server 2008 / r2) the logged on user object on some clients (windows 7) is added to the local administrator group.
I can't find the reason for this.
We have configured restricted groups in the strategy group and after gpupdate/force, the user is removed from the group yet (but administrator rights keep until the next logon).
Affected, it's always only the user who is logged on the client.
Of course, I checked the logon scripts, nothing that could trigger such behavior.
Does anyone have an idea how this could happen?
Thanks in advance,
Ingo

Hello

Your question of Windows 7 is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the IT Pro TechNet public. Please post your question in the TechNet Forum. You can follow the link to your question:

http://social.technet.Microsoft.com/forums/en-us/w7itpronetworking/threads

Hope the above information is helpful.

Tags: Windows

Similar Questions

  • Script to add a domain user to the local Administrators group raises the error "the network path is not found."

    I have a Windows Server 2008 R2 domain and a Windows XP Pro workstation that has been attached to the domain and then disconnected. I am trying to create a VBS script to add a domain user to the local Administrators group.

    I log on my computer as a local administrator and run the following script:

    Dim oNetwork: Set oNetwork = WScript.CreateObject ("WScript.Network")
    StrPC Dim: strPC = oNetwork.ComputerName
    Dim OGroup: Set oGroup = GetObject ("WinNT: / /" & strPC & "/ directors")
    Dim OUser: Set oUser = GetObject ("WinNT://domainname/username")
    oGroup.Add (oUser.ADsPath)

    This script returns the error "the network path is not found."

    However, I am able to go into control panel > user accounts > enter the user name and the domain name > click Next... > choose the administrators of the 'other' group and the user name will be added to the local Admin group.

    The same script runs without error if it is launched after logon on the workstation with a domain administrator account.

    How can I get my script runs without error, when you are logged into the workstation as a local administrator?

    Best regards, Andy

    The code that I used came from here. If the syntax of the Add method is passed to oUser.ADsPAth to "WinNT: / /" & domainname & "/" & username, the script works correctly.

    Therefore, the modified script:

    Dim oNetwork: Set oNetwork = WScript.CreateObject ("WScript.Network")
    StrPC Dim: strPC = oNetwork.ComputerName
    Dim OGroup: Set oGroup = GetObject ("WinNT: / /" & strPC & "/ directors")
    Dim strUser: strUser = "WinNT://domainname/username."
    oGroup.Add strUser

    Thanks to Qasim Zaidi to show the code of work here.

    Best regards, Andy

  • Where to find the local Administrators group?

    I wonder had to find what he's talking about if I change the number of Directors.

    Group members check Description

    This check identifies and lists the individual user accounts that belong to the local Administrators group. If more than two individual administrator accounts are detected, Microsoft Baseline Security Analyzer® will list the names of account and flag the check as a potential vulnerability. In general, we recommend that you keep the number of Directors to a minimum because administrators essentially have complete control over the computer.

    © 2002-2007 Microsoft Corporation. All rights reserved.

    NT TrustedInstaller service is necessary as an administrator?

    Yes.

  • Creating rule of compliance for the Add Group to the local Administrators group for the Machine.

    I try to write a compliance rule that can add an Active Directory group to a local group on a machine. For example the addition of our group of COMPUTER security in the local Administrators group on some machines.

    Any help with this would be greatly appreciated.

    DK

    The name refers on behalf of the group, so the first line is correct, but you must change the other Member who appoints the members of the group.  It would be like this, 'Member AS Server Ops % '.  I'm guessing that server Ops is a security AD Group, then you could also do "members = DOMAIN\Server Ops.  Usually best to select by pressing the 3 points and choosing from the available groups to make sure that you do not have typo and you have selected the correct attribute.

  • Domain users do not have local administrator rights, although I already added them in the local Administrators group

    I gave my domain users with local administrator rights. But they do not get the Control Panel, rights to open the network and sharing Center, and they could not change the registry... etc what is the solution for this? domain administrator I could be able to make any changes in this PC. We are facing this problem in all of our VMWare PC 7 on windows. I tried to add everyone in the local system Local Administrator and add the domain users group to the local administrator groups, but no luck...

    This issue is beyond the scope of this site and must be placed on Technet or MSDN

    http://social.technet.Microsoft.com/forums/en-us/home

    http://social.msdn.Microsoft.com/forums/en-us/home

  • user belongs to a domain and user does not belong to the local administrator or power users groups, or any custom group and the user is not part of the domain administrators group, but user show that it is admin

    WinXP
    user belongs to a domain and user does not belong to the local administrator or power users groups, or any custom group and the user is not part of the domain administrators group, but user show that it is admin

    I did a gpupdate/force and restart twice PC
    Yet, user indicate it is always admin when we right click on Start menu and see the possibility to open all users

    Hi elena_ad,

    Your question of Windows is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the public on the TechNet site. Please post your question in the below link:

    http://social.technet.Microsoft.com/forums/en/winserverManagement/threads

  • Groups and permissions of the user is added to the local disk post-conversion?

    We currently have a security policy with our Windows servers requiring admins to remove unnecessary security groups and users on the local disks. Basically, the SYSTEM and administrators retain full control, but all other users and groups are deleted for security reasons. We find that during a P2V conversion/clone servers, security groups and users are added to the readers of these new virtual machines (see screenshots below):

    Security before and after conversion. Could this be a function of the sysprep post-conversion tasks that work?

    Until now, we thought that, apart from the usual physical changes inherent to a clone, security remains unchanged. We follow best practices for conversion of these machines (running this as a local administrator account, run this converter installed on the machine, by stopping services as much as possible and so on).

    http://communities.vmware.com/servlet/JiveServlet/downloadImage/6174/pre-permissions.pnghttp://communities.vmware.com/servlet/JiveServlet/downloadImage/6181/post-permissions.png

    You can compare it to a system where you don't resize volumes, but all other factors are the same?

    If you reduce the size of a hard disk volume during the conversion, it will make a copy of file by file from the source to the destination devices.  We may have to add permissions for the conversion process, but I don't know if it is real.

    If you maintain or increase the size of the hard drive, it is a clone of block level which should be a bit-by-bit copy the source system.

    Kind regards

    EvilOne

    VMware vExpert 2009

    NOTE: If your question or problem has been resolved, please mark this thread as answered and awarded points accordingly.

  • Identify yourself to the local administrators not vCenter

    Hi there at - it configurations to allow ESXadmin in AD, but members are not local administrators of the server installed with Vcentre to be able to connect tnto Vcente?

    With the vsphere client, you will be able to select the permissions tab section which can be used to assign a role for this object in the vCenter inventory. There are 8 roles created by default, you may not create everything. In the permissions tab is where you can select a user AD or a group, assign these roles e. You can find the tab Permissions at different levels of the tree of the Virtual Center inventory.

    If you select Add permission, you will be able to match a local window or ad group or a user with a role of virtual Center. For example, I could say that my Windows AD user account can be an administrator of the Virtual Machine to a virtual server in the Virtual Center.

    Once this is done, they will be able to access the server vcenter vcenter server can reach an AD domain controller as

  • User duplicated on the Local disk folder

    Hello

    I was looking through the C: drive and found two user folders.  I went to the location of the folder of each and both were located on the Local disk and both had the same files folders and dates:

    Intel
    PerfLogs
    Program Files
    SwSetup
    Users
    WINDOWS

    I don't remember ever having seen two user folders.  Is it a normal thing?

    Thank you!

    M

    Hello

    1. how many accounts user are there on your computer?

    2. have you created a new user account?

    The files you mentioned are the same for all users.

    Please post the screenshot of the users folder that would help us helping you better.

    See the link.

    http://answers.Microsoft.com/en-us/Windows/Forum/Windows_7-security/how-do-i-post-a-screen-shot-on-this-forum/c86de820-C620-401c-A804-9f6337cd3053

    I also suggest you to download and run the latest Microsoft Scanner on your computer and check to see if it helps:

    http://www.Microsoft.com/security/scanner/en-us/default.aspx

    Note: the data files that are infected must be cleaned only by removing the file completely, which means there is a risk of data loss.

  • Error: Server not started when Service tried to share the drives on the local working group

    Original title: Server service not started

    I'm sharing my discs with another computer on my LAN to the working group. An error saying: the Server service has not started.

    I read the answer that you gave to use a previous restore point, but who can change my settings in the registry for other programs that were installed after the service for the Server service.

    Is there another way to do it?

    Hi mpccol,

    This can happen if the Srvsvc.dll library is missing or damaged. Try the steps mentioned inthis article and check the result.

    If you don't have a Windows XP CD, try the following steps:
    a. find the Srvsvc.dll on Windows file using the XP search feature.
    See How to search for files and folders in Windows XP
    b. copy the Srvsvc.dll present in the i386 folder and pasted to the location: : \Windows\System32 folder.
    Où : is the drive where Windows XP is installed.
    c. Once you have copied and replaced the file, restart the computer and check if the problem persists.

    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Printers under the original user have the printer properties grayed out for new users, even if they are members of the Administrators group

    Windows 7 Pro 64 bit (and 32-bit) Setup on the domain.
    The domain users group is added to the local Administrators group.
    Printers are installed under the first domain user.  These aren't the printers shared, but local usb printers or printers attached to the tcpip port and driver installed.
    All right.
    Users in the second domain is connected to the computer.  They are part of the local Administrators group, because they are part of the domain users group.
    They're going to look at the properties of the printer and almost everything is grayed out.
    Why?  Because they are part of the local Administrators group, they should not have full access?
    I look at security for printers and I don't see the first person in the list because it was created with their profile, but I also see local administrators that this new user belongs to a group.  Now I can take everyone and increase the rights and then log in as a new person and they can then change the properties, but why can't new users "who are admins the" does not alter the properties?
    Thanks in advance for your help.

    Hi Gsaunders,

    If the computer is connected to the domain network then the question you posted would be better suited in the TechNet Forums. I would recommend posting your query in the TechNet Forums.

    http://social.technet.Microsoft.com/forums/Windows/en-us/home?category=w7itpro&filter=AllTypes&sort=lastpostdesc

    It will be useful.

  • "To install the software, you must log on as a member of the Administrators group" when you try to install the printer software

    Original title: Installation software error

    I am trying to install a wireless printer Canon on my new laptop Dell with Windows 8 but I get error: to install the software, you must log on as a member of the Administrators group.  I'm naïve - I'm the only person who uses this laptop and have used the one and the only password for the connection.

    Solution... for me at least:

    (First of all, copy the installer to a flash drive)  I use Windows 7 Enterprise and have tried many combinations to run the installation program. The bit end who works is to restart the computer, connect to the machine as an administrator or another local user on the computer that is part of the local Administrators group, THEN Rclick Installer and run as administrator.

  • Local administrators on Windows of vCenter server is automatically granted 'Administrator' role in vSphere


    This still applies (5.0 and 5.5).  I might have missed in the 5 documentation site.  I see still ESX Admin workaround applies to 5.5 and wondered about the role of local administrators.

    VMware vSphere 4 - ESX and vCenter Server


    It's the 4.0 site doc.

    "Host records all selected Windows domain user, or a group through the process of assigning permissions." By default, all users who are members of the local windows Group istrators Adminthe vCenter Server have the same rights of access as any user assigned to the Adminsector role. Users who are members of the group Administrators can log on as individuals and have full access. »

    EDIT - I found this... VMware vSphere 5.1

    Seems to be the same... :))

    The main difference is that before 5.1 and 5.5, the local Administrators group on the server vCenter Server is the default vCenter Server Administrator. With vCenter 5.x with the addition of SSO, installing vCenter, you will be asked which user account or the group will be initially given and vCenter Server Administrator role. Here is the screenshot. This screenshot, after installing vCenter, only the [email protected] has the role of administrator on the vCenter server.

    If you upgrade your server vCenter to 5.x since a previous version using a Simple installation, if I remember correctly, you won't see the screen above as the installation will use the existing as the vCenter Administrator local Windows Administrators group.

    It will be useful.

  • access denied to the local system

    Hi all

    I have an Active Directory Server with windows Server 2008 R2 as a domain controller. Now when I install another system with windows 2008 r2 and then attach it to this area, unfortunately however I connection, then by a user who has domain admin lever, many local resources (such as the sql server service) do me not stop or start them and also when I try to change local group policy, many of its elements are gray and I can't change.
    I thought that if the domain administrators group is a member of the local Administrators group, that he can help me to access these resources, but it is wrong, can anyone help me?
     
    Hi Kamal
     
    The question you posted would be better suited in the TechNet Forums. I would recommend posting your query in the TechNet Forums.

    http://social.technet.Microsoft.com/forums/en-us/winserverfiles/threads

    Hope this information helps.
  • Windows could not start the IKE and Authip IPsec keying service modules on the local computer. Error 1075 the dependency service does not exist or has been marked for deletion.

    Hi, I'm trying start the IKE and AUTHOP service from the SERVICES screen but I get this error:

    Windows could not start the IKE and Authip IPsec keying service modules on the local computer.  Error 1075 the dependency service does not exist or has been marked for deletion.

    original title: ike and authip error 1075 the dependency service does not exist or has been marked for deletion

    Hello

    Remember to make changes to the computer before the show?

    You can follow the below methods:

    Method 1: Restart Windows and try to start the Security Center service.

    If you still receive the same error, make sure that the WMI service is launched and running:

    (a) click Start, run , and then type Services.msc

    (b) double-click Windows Management Instrumentation

    (c) set its startup type to Automatic

    (d) click Start to start the service, and then click OK

    (e) restart Windows.

    Method 2: Restart the service

    Windows logs an error if the service IKE and AuthIP IPsec Keying Modules or the driver does not start, or suddenly, they end.

    To restart the IKE and AuthIP IPsec Keying Modules service:

    To perform this procedure, you must have membership in the local Administrators group, or must you have been delegated the appropriate authority.

    (a) restart the service. You can do this from a command prompt or in the snap-snap-in Services Microsoft Management Console (MMC). Do one of the following:

    ·         Start an administrative command prompt. Click Start, click principally made programs, Accessories, right-click guest, and then click run as administrator. At the command prompt, run the command net start ikeext.

    ·         Click Start, type services.msc in the Search box and press ENTER. In the column name of the Services snap-in, right-click on IKE and AuthIP IPsec Keying Modulesand then click Start.

    (b) if the attempt to restart the service fails, restart the computer. This forces all related and dependent services to restart.

    (c) if the error persists after restarting the computer, then the executable files for the driver or service may be damaged, and the operating system must be reinstalled.

    Note:

    You can check that the IKE and AuthIP IPsec Keying Modules (IKEEXT) service runs by using the Component Services Microsoft Management Console (MMC) or the net start command line tool.

    You can check the link: http://technet.microsoft.com/en-us/library/cc733299 (WS.10) .aspx

    Method 3: Run a scan of the System File Checker.

    http://support.Microsoft.com/kb/929833

    It will be useful.

Maybe you are looking for