Can't add domain user account to local admin group properly
i have 2 windows 2008 servers. 1 domain controller, let's call dc , other sql box, let's call sql. so, want setup domain user account can use on sql box. sql box has been added dc's domain. setup domain user account in active directory. navigate computers , select manage on sql box. navigate administrators group, , add domain user account created.
once that, , go administrators group (for sql box) in active directory, sid listed domain user account instead of actual user name. if try , login sql box domain user account, able login, if attempt perform admin activity, don't have permissions so. if on sql box (and login local admin), , navigate , open administrators group, there is no domain user account listed.
so, able login sql box domain account, don't have local admin priviledge reason. have set windows firewall off on both dc , sql box. doesn't seem help.
i @ loss try next. thoughts?
thanks.
hi,
based on research, group policies may cause 'sid can't correctly translated friendly name' issue. please run 'rsop.msc' on problematical pc see if following group policies set:
under computer configurations\windows setting\security setting\ security options\
network access: allow anonymous sid\name translation enabled
network access: not allow anonymous enumeration of sam accounts disabled
network access: not allow anonymous enumeration of sam accounts , shares disabled
network access: let permissions apply anonymous users enabled
network access: named pipes can accessed anonymously enabled
network access: restrict anonymous access named pipes , shares disabled
client pc need contact dc translate domain user sid friendly name. there possibility client machine may not contact dc @ time, sid may not correctly translated. please wait longer time see result. also, please check if client pc's dns has correctly pointed dc or dns server.
if symbol persists, please check if there error message in event viewer on dc , client.
Windows Server > Directory Services
Comments
Post a Comment