Problems creating a Domain Administrator Account in AD
I am trying to create a Domain Administrator account so admins can logon to PCs and make changes.
I've done this, by creating a new user on the DC in AD, then adding them to the "Domain Admins" group.
However when I logon with this new account, I don't get full admin rights on the local machine OR on the DC - for instance, I can't change security settings in Internet Explorer.
This is a fresh install of Windows Server 2008 Standard. There are no Group Policies that apply to this account (I've double checked) and no other restrictions that I can see.
"Domain Admins" is definitely also a member of the Builtin/Administrators group.
In order to check I've not gone mad, I've created another account using this very basic step by step video here
YouTube - 𠊬reating a personal domain Administrator account Server 2008 - AD DS‬‏
And still I don't seem to have full local admin rights.
Am I missing something obvious?