Jump to content

Domain user becoming administrator even though not a member of the security group?


Recommended Posts

Posted

As title really.

Domain users are becoming an admin even though they are not a member of the administrator’s security group. How???

I've narrowed it down to a security group (If I add a user to this security group they become an admin, if remove they become non admin)

This security group is a member of other security groups, however I’ve checked through all the groups and NOT one of them is a member of administrators, domain admins etc. etc.

I've checked the local security group on the computer and they are not set as an admin there. I've checked gpo's (and this week made new gpo's for Windows7) and there is nothing in them to make this security group become an administrator.

 

What else could it be?:smash:

Posted

What happens when you add another user to this group that causes admin rights?

 

If they in turn get elevated rights, you might have missed a group membership in your search.

 

Just a starting point.

 

Ben

Posted
What happens when you add another user to this group that causes admin rights?

 

If they in turn get elevated rights, you might have missed a group membership in your search.

 

Just a starting point.

 

Ben

 

Thanks for the reply Ben.

Tested what you suggested

 

1) Made new account and did not add to the security group mentioned in first post.

2) Logged on client as this new user to see if it had admin rights ( It Didn’t)

3) Logged off and added the new user to the affected security group

4) Logged on client as this new user to see if it had admin rights (It Didn’t)

5) Restarted client

6) Logged on client as this new user to see if had admin rights ( It did )

 

Security groups shouldn’t require a restart to take effect? Or should they? Maybe it's something set on the computers in AD.

I'll check through all the groups again incise I missed something and one is a member of administrators.

Posted

Perhaps have another look at group policy? user group membership takes affect at log off / on so its not that i believe. but group policy's can often take a restart to kick in.

 

Is there anything in the event logs? and do you still have the same effects on a different client machine?

Posted

Had a look through all the groups and the only group is power users is a member of domain users ( Which I dont beleive is needed ) all the rest are fine.

Group policy should be fine because I created all new from scratch this week. The user and computers are only getting the policys I made so it cant be that ( This problem occured on the old gpo's as well )

I'll check the event logs. Not really sure what else do

Posted
Checked the local admin group on the machines?

 

What this makes no sence. Honestly I checked the local admin group before and none were a member. I just checked now and this group thats affected is !!

Now to work out whats causing this -.-

Posted

Ok..I cant find anything. Hope i'm not being dumb but this is really driving me crazy.

 

I know this = The security group is somehow becoming a member of the local admin group

 

1) This group isnt a member of administrators on the server

2) No group policy is causing this

3) No logon script is causing this

 

I'm really out of ideas of what else can make this group a member of admins

Posted
its sounds like there is a gpo which is adding this security group to the local security group - i would run gpresult and see which policys are being applied and hunt it down from there.
Posted
its sounds like there is a gpo which is adding this security group to the local security group - i would run gpresult and see which policys are being applied and hunt it down from there.

 

Nope. Already done. Plus I re-made all the group policy’s this week that are being applied to this computer/user and I’ve 100% not set it to make this group as a local admin. The only other policy that’s being applied is the default domain policy (Only one I didn’t remake and nothing is set there to do this either)

Posted
Nope cant see it set there. It happens on all computers so must be something from the network.

 

We have this on our Windows 7 Enterprise machines. Users can go for days/weeks without any issues and then all of a sudden they log into a machine and are given full access to everything - it's as if they have become full machine/network admins.

 

We got around it by rebuilding the machine. The issue went.

 

Could it be something in the default user profile?

 

Gareth

Posted
Nope cant see it set there. It happens on all computers so must be something from the network.

 

not nessicarly as if they are all built from the same image it can be applied through something from there

Posted
not nessicarly as if they are all built from the same image it can be applied through something from there

 

True.

I made these images just before the summer started though and I most certainly didn’t add this group as a local admin. Someone else could of done It I suppose (Not sure why they would do that) Where would I look in the default profile to see if it’s coming from that?

I guess the test to see if it's coming from the image is to check the administrator’s group members before the script runs that joins the computers to the domain. Could it possibly be the sysprep file I created adding the group? I'll give that a check.

Would like to know what's causing this, because it's a bit of a concern having members become administrators and not even know why/what’s causing it. To prevent it until I find the cause I can at least set a policy or script to remove these from the admin group.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...