Athlona Posted October 27, 2008 Posted October 27, 2008 Hi I have a teachers AD account that seems to have a problem, Her account member of are correct but she can see the C drive and list of mapped servers which she shouldn't be able to see!!! Is it likely her AD account has just become corrupt or is it something more sinister? Any advise on this matter would help me sleep Thanks
penfold Posted October 27, 2008 Posted October 27, 2008 Did they have an admin level access previously? Is this on only 1 client? If so, run Delfpof and then gpupdate /force on the client. Reboot and see if they come back. If it is on more than 1 client then it must be some settings on the server side. Do you have any logon scripts running also?
Athlona Posted October 27, 2008 Author Posted October 27, 2008 Its only one user thats having the problem with her roaming profile on any client PC she logs onto!!! Delete account create a new one me thinks??? or is there a FIX?
srochford Posted October 27, 2008 Posted October 27, 2008 What should stop her seeing the C: drive? Is this a group policy setting? If so, have group policies applied successfully (do a gpupdate /force and check the event log) Does the problem just happen on one machine? If so, then suspect the cached copy of the profile or the process which applies group policies (if you have a 1202 error in the event log then you can google for that - the event log message tells you what to look for!)
Athlona Posted October 27, 2008 Author Posted October 27, 2008 (edited) Group policy is setup to hide the C Drive!!! I have just disabled her AD account and still her account is able to logon!!! Will try gpupdate... The problem shows up on all computers I have tried to logged on as her!!! Edited October 27, 2008 by Athlona
Gibson335 Posted October 27, 2008 Posted October 27, 2008 Is she potentially logged on somewhere else? Also, before deleting the user account it's always an idea to first delete any relevant profiles - local and redirected to see if that irons out any issues - though this one is an oddity that sounds more like a GP issue. Is she somehow not in the right OU...sometimes a user can be accidentally moved!! Worth checking.
Athlona Posted October 27, 2008 Author Posted October 27, 2008 She's in the correct OU moved her out of the correct OU to a different one and still she it didn't work!!! Looks like a GP problem Mine Field of possible problems!!! but out of the 5 PE teachers she's the only one having problems...
srochford Posted October 27, 2008 Posted October 27, 2008 if you log on as her and run gpresult /v then what result to you get - this should tell you what's going on and I suspect will say that there's a problem applying the particular GPO. It might also give a hint as to why there's a problem.
Athlona Posted October 27, 2008 Author Posted October 27, 2008 ran a gpupdate /force pc restarted but again group policy hasn't been applied to her AD account!!! But whats more upsetting is she can see all the servers and doesn't even ask for a administrator or password to access them!!!
apeo Posted October 27, 2008 Posted October 27, 2008 Does this user still have access if you disable it? If that is the case then its not only gp thats the problem it would seem.
Athlona Posted October 27, 2008 Author Posted October 27, 2008 There me thinking I was going to have a chilled out half term LOL... When disabled within AD her account still lets her in!!! Is It likely someone has been hacking at her account??? Just been told she sometimes gives her password out to student TEACHER!!!!!!
timzim Posted October 27, 2008 Posted October 27, 2008 Is her surname Dministrator and her first name Anita by any chance?
apeo Posted October 27, 2008 Posted October 27, 2008 (edited) Is her surname Dministrator and her first name Anita by any chance? LOL @Athlona: Just to clarify, user was not logged on anywhere when the account was disabled? Resetting the password is probably a good idea too. EDIT: as to giving access to Teacher accounts to students, well over here that a violation of the AUP and I would report to my manager who will no doubt tell the head. Teacher probably wont do that again in a hurry. Edited October 27, 2008 by apeo
Athlona Posted October 27, 2008 Author Posted October 27, 2008 Timzim how did you guess her name...? LOL Hi apeo no she wasn't logged in anywhere its half term schools out... First thing I tried was to change the password that has worked in the past with strange problems:)
timzim Posted October 27, 2008 Posted October 27, 2008 Joking apart, can users log onto PCs locally (i.e. not using the domain)? If so then is there any chance she's logging on locally, and her local account/s has/have admins rights? If you've disabled her AD account (and it's not being re-enabled by someone else????) then there's no way she should be able to log on using it. Are you the only member of Domain Admins or are there others and, if so, have any of those accounts (or yours) been compromised? Maybe remove/disable/delete any unnecessary Domain Admins accounts then change passwords on all those remaining.
ZeroHour Posted October 27, 2008 Posted October 27, 2008 Are your DC's replicating properly? When you disable her account force replication and see if she can get in again.
srochford Posted October 27, 2008 Posted October 27, 2008 ran a gpupdate /force pc restarted but again group policy hasn't been applied to her AD account!!! But whats more upsetting is she can see all the servers and doesn't even ask for a administrator or password to access them!!! What does it say in the event log after you've run gpupdate - you should get a message saying the group policy was applied successfully. If that's not there then GP hasn't applied (the reboot would be caused by the machine bit of group policy but you seem to have a fault with the user part). Have you run a gpresult? What results does it give? Is it listing the GPO that should be preventing access to the C: drive? When you say she can see the servers, what do you mean? Just browsing network neighbourhood? If so, this is exactly what should happen unless there's a group policy to block it (and it does look as if GP is not applying properly - you've not yet said whether it is or isn't). I also don't understand what you mean about asking for a password - if I type "\\server" into explorer I'd expect to see a list of share names with no prompt for a password. I'd only get prompted for a password if I tried to connect to a share to which I shouldn't have access - is this what you're seeing? If you check the properties of the user, what groups is she in? - Check each group in case somehow a group has moved into administrators or similar "powerful" group.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now