Quantcast
Channel: Directory Services forum
Viewing all articles
Browse latest Browse all 31638

"Builtin Administrators" account is missing

$
0
0

Hello - I am getting the following error:

Title:
Domain controller XXXX.XXXX.XXX must have "Access this Computer from the Network" granted to the appropriate security principals

Severity
Error

Date:
4/12/2013 9:29:27 AM

Category:
Configuration

Problem:
Domain Controller XXXX.XXXX.XXX does not have user right "Access this computer from the network" granted to 'Builtin Administrators', 'Enterprise Domain Controllers' or 'Authenticated Users', or has the user right "Deny access to this computer from the network" assigned to either of those groups or 'Everyone'.

Impact:
Replication operations initiated by other domain controllers in the domain or by administrators may fail. Users and computers may also experience failure to apply Group Policy objects.

Resolution
Verify that the domain controllers in the domain XXXX.XXX have this user right granted to the appropriate security principals. Using Group Policy Management and Group Policy Results, verify that the winning Group Policy for the "Access this computer from the network" user right grants that right to the 'Builtin Administrators', 'Enterprise Domain Controllers', and 'Authenticated Users' groups. Verify that the policy setting "Deny access to this computer from the network" does not have 'Everyone', 'Authenticated Users', 'Builtin Administrators' or 'Enterprise Domain Controllers' groups defined in it.

http://go.microsoft.com/fwlink/?LinkId=168844

*******************************************************************************************************************

I found a similar post on the TechNet forum but it did not give the final solution.
http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/dd37baf9-0d15-4522-b473-86a1e1aae486/

Running
dsquery user -name Administrator | dsget user -memberOf

"CN=E2E_Admins,CN=Users,DC=XX,DC=XXX"
"CN=AD1 $ Acronis Remote Users,CN=Users,DC=XX,DC=XXX"
"CN=Exchange Admins,CN=Users,DC=XX,DC=XXX"
"CN=Administrators,CN=Builtin,DC=XX,DC=XXX"
"CN=Schema Admins,CN=Users,DC=XX,DC=XXX"
"CN=Enterprise Admins,CN=Users,XX,DC=XXX"
"CN=Domain Admins,CN=Users,DC=XX,DC=XXX"
"CN=Group Policy Creator Owners,CN=Users,DC=XX,DC=XXX"
"CN=Domain Users,CN=Users,DC=XX,DC=XXX"

Running
dsquery * -filter "(objectSID=S-1-5-32-544)"

"CN=Administrators,CN=Builtin,DC=XX,DC=XXX"

As I read the previous postings on the error - I get the idea that the computer thinks that the local administrator account is not part of the Built-In Administrators Container.
The query <dsquery user -name Administrator | dsget user -memberOf>
shows that "CN=Administrators,CN=Builtin,DC=XX,DC=XXX"

Based on the TechNet article
http://technet.microsoft.com/en-us/library/ff646935(v=ws.10).aspx

"Verify that the security groups Builtin\Administrators, NT Authority\Enterprise Domain Controllers, Everyone, or Authenticated Users are not defined in this policy setting."

There are not users or groups added to this GPO

**************************************************************************
DCDiag passes all tests


Viewing all articles
Browse latest Browse all 31638

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>