Unable to Remove "Domain Users" from Builtin\Administrators Permanently


i have seen other similar posts i've not been able come solution. when go aduc , remove default domain users group "administrators" repopulate group. @ first seem that's gpo. however, there aren't configuring restricted groups or gpp. running gp results wizard confirms same. have looked @ admincount attribute well. set <not set> on both domain users group , builtin\administrators group.

honestly, i'm @ complete loss on one. i've removed group half dozen times , continues reappear. tried creating gpo had of existing members minus domain users group. group still doesn't removed (even though did have desired effect on non-domain controllers). can add/remove individual users administrators , stay out. seems limited group.

there no scripts in policy running @ startup or in task manager.

question is, cause group reappear in builtin\administrators isn't group policy, isn't admincount, , isn't script?

os: windows small business server 2011 standard

-shep

sorry delay. found script buried in on of policies setting it. once removed no longer had issue. our fear goofy door former admin left or lazy. either way, it's fixed now. difficult find.

-shep



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group