Domain Admin can't log into child domains

Domain Admin can't log into child domains

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Domain Admin can't log into child domains Ageing Brillian 02-15-2006
Posted by =?Utf-8?B?QWdlaW5nIEJyaWxsaWFu on February 15, 2006, 7:19 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
We have 2 domains - a parent and a child. They are separated physically - 2
different buildings. Administrators in the child domain can log onto any of
the servers in the parent domain (via terminal services, or physically
sitting at the console) using their child domain credentials (ie
username/password/child-domain-name), however administrators in the parent
domain cannot log onto servers in the child domain (via terminal services, or
physically sitting at the console) using their parent domain credentials (ie
username/password/parent-domain-name). Howcome?

Posted by Roger Abell [MVP] on February 16, 2006, 12:44 am
If you were  Registered and logged in, you could reply and use other advanced thread options
It is that way because someone has set it up that way.
Domain Admins can only log into their own domain in the
default. Enterprise Admins are granted wide-spread rights
in all domains. That is all changable.
The things you need to examine are:
memberships in the Administrators and Domain Admins
groups of each domain
memberships in the Enterprise Administrators group
failing finding them in the above then check Users
grants of terminal services login, either via the Remote
Desktop Users group or directly in the permissions
on the RDP connectoid in the TS config mgmt applet
grants of the Log on locally user rights (for example, you
did not say child DAs are admins in the parent, only that
they could log into the boxes of the parent)
"Ageing Brilliantine Stick Insect"
> We have 2 domains - a parent and a child. They are separated physically -
> 2
> different buildings. Administrators in the child domain can log onto any
> of
> the servers in the parent domain (via terminal services, or physically
> sitting at the console) using their child domain credentials (ie
> username/password/child-domain-name), however administrators in the parent
> domain cannot log onto servers in the child domain (via terminal services,
> or
> physically sitting at the console) using their parent domain credentials
> (ie
> username/password/parent-domain-name). Howcome?



Similar ThreadsPosted
domaine vergabe free de domains domain de eu domain name registrieren de be domain July 28, 2008, 4:14 pm
CAs: Enterprise root on parent domain, subordinate on child domain March 20, 2008, 10:28 am
Domain Admin administering Domain Computers December 6, 2005, 2:58 am
Secured domain admin using MMC Snapins November 21, 2007, 10:26 am
2000 Domain Admin Security Best Practices October 17, 2005, 11:50 pm
How do I manage local admin accounts without a domain or ADS? November 16, 2005, 6:22 pm
Problem with Domain Admin becoming Administrator (builtin) April 11, 2006, 10:08 am
Built-in domain admin account password will expire January 3, 2007, 3:03 pm
Why can domain users access to admin shares on my servers? June 25, 2008, 8:46 am
Child proofing July 31, 2006, 8:15 pm

The site map in XML format XML site map

Contact Us | Privacy Policy