Mark Minasi's Reader Forum
Mark Minasi's Reader Forum
Home | Profile | Register | Active Topics | Active Polls | Members | Search | FAQ | Minasi Forum RSS Feed
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 HALP! Questions on Windows and Windows Server
 Windows Server 2008 R2
 When is a domain admin not a domain admin? (UAC)
 New Topic  Reply to Topic
 Printer Friendly
Author Previous Topic Topic Next Topic  

Pesos
Honorable But Hopeless Addict

USA
3506 Posts
Status: offline

Posted - 05/08/2012 :  3:10:58 PM  Show Profile  Reply with Quote
So we have noticed that on 2008r2 and win7 boxes, members of the domain admins group seem to be watered down by UAC. The default "administrator" account seems to be automatically exempted from UAC on all machines, but other domain admins are not, leading to administration hassles when these users try to change file server permissions or install msi files, etc

What is special about the administrator account and how do we extend this specialness to all domain admins without disabling UAC?

-Wes

chamezzzz
Honorable But Hopeless Addict

United Kingdom
2298 Posts
Status: offline

Posted - 05/09/2012 :  09:49:38 AM  Show Profile  Reply with Quote
Hi Wes,
What I believe happens is the Domain Administrator account has Admin Approval mode for UAC disabled by default.
So too does the Windows 7 Local Administrator account, which is also disabled by default in Windows 7.
I think you need to apply group policy to your Domain Admins so that

"User Account Control: Use Admin Approval Mode for the built-in Administrator account" is disabled"

http://windows.microsoft.com/en-GB/windows7/User-Account-Control-Use-Admin-Approval-Mode-for-the-built-in-Administrator-account

Because the accounts you subsequently create in Domain Admins are not *default accounts* but *additional accounts you have created* Admin Approval mode is enabled for them.

I can't find anything on Microsoft Support site to confirm this, hope this points you in the right direction.

Regards

EDIT - this is where I am getting my assumption from
http://technet.microsoft.com/en-us/library/dd446675(v=ws.10).aspx
http://goo.gl/Lbzvy

No mention of the initial Domain Administrator account. I am assuming that the initial Domain Administrator account is treated the same as the built-in Administrator account. It explains the behavior you are seeing.

The built-in Administrator account in Windows Server 2008 R2 does not run in Admin Approval Mode

The built-in Administrator account in Windows Server 2008 R2, which is the first account created on a server, does not run in Admin Approval Mode. All subsequently created administrator accounts in Windows Server 2008 R2 do run in Admin Approval Mode.

The built-in Administrator account is disabled by default in Windows 7

The built-in Administrator account is disabled by default in Windows 7. The built-in Administrator account, by default, cannot log on to the computer in Safe Mode.

James

Edited by - chamezzzz on 05/09/2012 09:57:53 AM
Go to Top of Page

Pesos
Honorable But Hopeless Addict

USA
3506 Posts
Status: offline

Posted - 06/22/2012 :  2:57:22 PM  Show Profile  Reply with Quote
Thanks James - we applied this admin approval mode, and once the policy is picked up and boxes rebooted, it works. HOWEVER, it has an annoying side effect. It appears to alter the way in which UAC works. Prior to this change, when we were logged in as a regular user, we could elevate to do admin tasks by simply signing in when the UAC prompts popped up. This admin approval mode appears to basically disable UAC altogether so UAC prompts don't appear. We have to actually switch user and log in as domain admin to get anything done, which is a bit of a hassle.

What is so special about the standard builtin administrator account that lets it bypass all this annoying rigamarole?

-Wes
Go to Top of Page

Pesos
Honorable But Hopeless Addict

USA
3506 Posts
Status: offline

Posted - 06/22/2012 :  3:15:40 PM  Show Profile  Reply with Quote
Looks like this guy explains what I am seeing, and Microsoft really does a poor job with their labeling:

http://thehunk.blogspot.com/2008/10/messing-with-uac-admin-approval-mode.html

-Wes
Go to Top of Page

JeffWouters
Here To Stay

Netherlands
147 Posts
Status: offline

Posted - 06/24/2012 :  07:07:34 AM  Show Profile  Visit JeffWouters's Homepage  Click to see JeffWouters's MSN Messenger address  Look at the Skype address for JeffWouters  Reply with Quote
Search for a session called "Raiders of the elevated token" by a Dutch Windows Client MVP named Raymond Comvalius.
He explained the answer to this question beautifully :-)

Greetsz,
Jeff.
Go to Top of Page

chamezzzz
Honorable But Hopeless Addict

United Kingdom
2298 Posts
Status: offline

Posted - 06/26/2012 :  04:46:51 AM  Show Profile  Reply with Quote
No worries Wes, although a complete educated guess rather than experience in this.
I think this is the Link Jeff mentions.
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WCL325


James
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Reply to Topic
 Printer Friendly
Jump To:
Mark Minasi's Reader Forum © 2002-2011 Mark Minasi Go To Top Of Page
This page was generated in 0.44 seconds. Snitz Forums 2000