Quantcast
Channel: Group Policy forum
Viewing all articles
Browse latest Browse all 19997

Windows Server 2016: Domain Admins cannot create/modify any file/folder on any partitions of Domain Controllers

$
0
0

Hi,

all members of "Domain Admins" built-in group cannot create/modify any file or folder on any partitions of Domain Controllers.

If domain admin logs on any DC and create/change, then the access is denied.

If the domain admin start Windows Explorer or PowerShell, etc. in elevated mode, then he can create/change any files/folders.

I know that  is related to UAC.

I cretaed a GPO, set UAC settings correctly and applied it to "Domain> Domain Controllers" OU for the Group"Domain Admins". But this did not solve also the issue.

Domain Controller Local Security Policy has another settings (UAC enabled). As I know the GPO on the OU level has the highest priority on applying of GPOs. Is DC an exception? If yes, how can solve this issue?

Best regards

Birdal


Viewing all articles
Browse latest Browse all 19997

Latest Images

Trending Articles



Latest Images