PDA

View Full Version : Cannot Add Domain User to Local Administrator Group


spislgal
Mar 7, 2007, 02:24 PM
I am trying to add a domain account to the local Administrators group on a Windows XP Pro workstation. My network is Windows 2003 / Active Directory.

On a Windows XP workstation:

Administrative Tools > Computer Management > Local Users and Groups > Groups

I open the Administrator group, then press "Add..." The only thing in the "From this location" box is the local machine I'm working on, so I press the "Locations" button. In the resulting window, there is no other option to select from. The only icon in that window is the local machine.

Consequently, I cannot add a domain account to the local Administrators group.

Notes:

--The Domain Administrator and a Local user account are currently part of the machine's administrator group.

--Able to login on the machine as Domain administrator

-- The computer has been added to the domain. Active directory is completely aware of the machine and it functions normally in the domain aside from this issue.

-- Was able to login as the domain user on the machine and a profile was created. However, need to add the domain user account to local admin group to be able to run/test a program.

Curlyben
Mar 7, 2007, 02:30 PM
Try this on the local machine.
Start > Control Panel > User accounts > Add the user there with the domain info. To local admin.

Tushars
May 11, 2007, 12:20 AM
I am trying to add a domain account to the local Administrators group on a Windows XP Pro workstation. My network is Windows 2003 / Active Directory.

On a Windows XP workstation:

Administrative Tools > Computer Management > Local Users and Groups > Groups

I open the Administrator group, then press "Add..." The only thing in the "From this location" box is the local machine I'm working on, so I press the "Locations" button. In the resulting window, there is no other option to select from. The only icon in that window is the local machine.

Consequently, I cannot add a domain account to the local Administrators group.

Notes:

--The Domain Adminstrator and a Local user account are currently part of the machine's administrator group.

--Able to login on the machine as Domain administrator

-- The computer has been added to the domain. Active directory is completely aware of the machine and it functions normally in the domain aside from this issue.

-- Was able to login as the domain user on the machine and a profile was created. However, need to add the domain user account to local admin group to be able to run/test a program.
Can you please tell me what is your achievements?

iali
Jul 11, 2008, 09:47 AM
If you still have this problem, just go to the computer management ==> groups > Administrators ==>Add==>domain name \username

And you sholud be good to go.

You can do this by group policy as well.

Thanks,

Irfan Ali.

chuckhole
Jul 11, 2008, 02:13 PM
If the computer is unable to browse the domain even though the machine is a member of the domain, it may have a corrupt machine account. Go to the Event Logs and look in the System Log. Do you see any Kerberos errors or DCOM errors?

The best step to take is to remove the machine from the domain and then add it back to the domain. Make sure you know what the local Administrator account password is before your reboot.

khan021
Jul 12, 2008, 11:25 AM
I go with irfan ali.

I think it will work for this.

yourcomputerguy
Jul 12, 2008, 08:20 PM
Hello,

Please verify that your xp workstation has ONLY the DNS entry for your dns server/domain controller.

You can check/change this by:
Control panel > network > right-click the network connection used > properties > tcp/ip (properties)

Also, of course, ensure the workstation is on the same local network as your domain controller, or properly connected by a vpn if that's your thing.

dgobat
Sep 15, 2009, 02:38 AM
yourcomputerguy your solution fixed my issue.

I set the Preffered DNS Server address to point to my DNS, logged off and logged back on and it worked.

Thanks!

misidro
Aug 22, 2012, 10:24 AM
Hello,

Thanks for the help! It solved my problem too!

Regards,


Hello,

Please verify that your xp workstation has ONLY the DNS entry for your dns server/domain controller.

You can check/change this by:
Control panel > network > right-click the network connection used > properties > tcp/ip (properties)

Also, of course, ensure the workstation is on the same local network as your domain controller, or properly connected by a vpn if that's your thing.