Can't add domain user account to local admin group properly


hi,

i have 2 windows 2008 servers.  1 domain controller, let's call dc , other sql box, let's call sql.  so, want setup domain user account can use on sql box.  sql box has been added dc's domain.  setup domain user account in active directory.  navigate computers , select manage on sql box.  navigate administrators group, , add domain user account created.

once that, , go administrators group (for sql box) in active directory, sid listed domain user account instead of actual user name.  if try , login sql box domain user account, able login, if attempt perform admin activity, don't have permissions so.  if on sql box (and login local admin), , navigate , open administrators group, there is no domain user account listed.

so, able login sql box domain account, don't have local admin priviledge reason.  have set windows firewall off on both dc , sql box.  doesn't seem help.

i @ loss try next.  thoughts?

thanks.

 

hi,

 

based on research, group policies may cause 'sid can't correctly translated friendly name' issue. please run 'rsop.msc' on problematical pc see if following group policies set:

 

under computer configurations\windows setting\security setting\ security options\

 

network access: allow anonymous sid\name translation enabled

network access: not allow anonymous enumeration of sam accounts disabled

network access: not allow anonymous enumeration of sam accounts , shares disabled

 

network access: let permissions apply anonymous users enabled

network access: named pipes can accessed anonymously enabled

network access: restrict anonymous access named pipes , shares disabled

 

client pc need contact dc translate domain user sid friendly name. there possibility client machine may not contact dc @ time, sid may not correctly translated. please wait longer time see result. also, please check if client pc's dns has correctly pointed dc or dns server. 

if symbol persists, please check if there error message in event viewer on dc , client.

 

 



Windows Server  >  Directory Services



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file