Registered users    
MembershipMembership:
Latest New UserLatest:Martin Baker
New TodayNew Today:4
New YesterdayNew Yesterday:7
User CountOverall:23063

Private messaging    
You must be logged in to use this module.
Top 10 posters    
NamePosts
Mariette Knap12622
Marina Roos12280
Eriq Neale2105
Michael Patrick1906
Stan Guinn1840
Robert Pearman1724
Nick Pieters1425
Stewart Brown609
Kevin D.563
william warren548
Welcome unauthorized visitor    
If you want to join us in the discussions on this forum you need to register first. Registration is free! If you are already a registered user please login to join the forum.
Small Business Server Support Forum    
Subject: Problem after removed "domain users" from "local administrator"s group!
Prev Next
You are not authorized to post a reply.

Author Messages
Tammy Heal User is Offline
Canada
Member since
5/19/2005

Platinum Membership
Posts: 91

7/08/2008 11:20 PM  
Hello all,
 
We are running SBS 2003 SP1 Premium with approx 14 workstations running Windows XP Pro SP2.
 
We finally decided to remove the "domain users" group from the "local administrators" group on the workstations and since doing that we have a strange problem happening.
 
The users can log on the network successfully but then they can not start any programs - as soon as I reverse this setting everything is fine again.
 
This does not make sense to me - has anyone come across this before?  We want this setting to tighten up on security...so users can no longer install applications, etc.
 
If anyone has any suggestions on how to fix this that would be great!!
 
Thanks so much in advance!
Tammy 
Kevin Da Silva User is Offline
Mississauga, Canada
Member since
1/12/2008

Registered Users
Posts: 563

7/14/2008 10:15 PM  
Can the user start Paint? Do they get any errors?

Could the applications have been installed as the local admin thus causing an issue with permissions?

MCSE:Messaging, MCTIP, SBS Specialist
Kevin Da Silva User is Offline
Mississauga, Canada
Member since
1/12/2008

Registered Users
Posts: 563

7/14/2008 10:15 PM  
Also have you added them to another group on the machine?

MCSE:Messaging, MCTIP, SBS Specialist
Tammy Heal User is Offline
Canada
Member since
5/19/2005

Platinum Membership
Posts: 91

9/12/2008 11:04 PM  
Hello Kevin - thank you for your replies.  I am back to working on this issue now!
 
To answer your questions - yes - the users can start Paint.  When they try to start Outlook - for example - they just receive an error saying that Outlook can not be started.  None of the items in their startup group start either.
 
Again our goal is to remove the "domain users" from the local "administrators" group so they can not install software, etc.  I tried adding "domain users" to the "power users" group and the same problem occurs.
 
The applications would have been installed as either the domain user or the domain administrator - not as the local administrator.
 
This is very strange indeed and I am hoping to resolve soon!  Would you happen to have any other ideas as to what might be causing this?
 
Thank you again!
Tammy
Tammy Heal User is Offline
Canada
Member since
5/19/2005

Platinum Membership
Posts: 91

9/12/2008 11:09 PM  
Forgot to mention - I also noticed that when I remove the "domain users" from the local "administrators" group that the users can not attach to their computer via RWW unless I added "domain users" to the local "remote desktop users" group.....
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12280

9/14/2008 07:01 PM  
Hi Tammy,
 
Were the computers and the users added with the wizards? Any errors in the eventlogs on the comuters?

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
You are not authorized to post a reply.
Forums > Microsoft Smallbusiness Server > Small Business Server 2003 > Problem after removed "domain users" from "local administrator"s group!



ActiveForums 3.7
Forum policy    
These Discussion Forums are dedicated to the discussion of the Small Business Server and related server and client software. For the benefit of the community please observe the following posting guidelines:
  1. No Advertising. This includes promotion of commercial products and non-commercial products which are not directly related to Small Business Server and related server and client software.
  2. No Flaming or Trolling.
  3. No Profanity, Racism, or Prejudice.
  4. Site Moderators have the final word on approving/removing a thread or post or comment.