Domain users and the super admin account

Christian

New member
Local time
4:16 AM
Messages
1
Hey all,

I have recently installed Windows 7 on my development machine at work primarily in order to test it and get a feel for it and all the little things that can go wrong before the IT department I work for roll it out to all the other employees at the company. (They're still on XP SP 3).

Unfortunately, I'm experiencing several crippling issues caused by the stricter administration model used in Windows 7 (and Vista, for that matter) compared to Windows XP. We have programs crashing or refusing to install or run because they were designed for XP and require admin rights. So when they're unable to acquire them from Windows 7, the programs throw exceptions. An example of this is Trend Micro OfficeScan, a popular antivirus program used in many companies. This program is caused to install by start-up scripts that are run when you log on to your computer using your domain username and credentials, but the installer crashes, because the domain user is not a local super admin.

And that's the core of this question. I want my domain user to have full administrative privileges. I've done a lot of research on this particular problem and I realize it's possible to activate a special super admin-account that has full access to everything on the computer, but that workaround doesn't cut it for me, because the only thing that accomplishes is to make the super admin account available for login, but the super admin account is not a domain user at my company's network, it is a local user. It doesn't have access to the company's network resources and therefore, it is useless to me. What I want, is for my domain user and credentials to have super admin privileges.

Is that possible in Windows 7? I am essentially looking for a way to elevate any user of a system to have the same privileges as the super admin account. I realize this is a potential security risk because everybody and everything has access to installing everything on the system, but frankly, the amount of software that Windows 7's security model causes to malfunction due to too strict security features is too high a price to pay.

In many cases, it corresponds to pulling the network cable out of the wall: Sure, you won't get attacked by malware, but you won't get any work done either.

Any and all help appreciated. :)
 

My Computer My Computer

Computer Manufacturer/Model Number
Dell
OS
Windows 7
CPU
Intel P4 3.0GHz
Motherboard
Unknown
Memory
3 GB
Graphics Card(s)
Some business-card from Nvidia that enables dualmonitor
Sound Card
None
Monitor(s) Displays
Two dells
Hard Drives
Unknown
PSU
Unknown
Case
Unknown
Cooling
Unknown
Due to the Dual token design of the security model in use you will have issues with applications designed for the older model.

The solution to this need not be an all or nothing one however, It should be possible to give the required installer rights to the user group(s) concerned, directly.

This may be done universally to the complete program files folder(s) or more usefully to individual folders for the older problem apps.

I have seen situations where a non working older program can be made to work/Install by the granting a standard user full access rights to a single settings file or to the installation folder.

Depending on what you desire as a company you can make some groups allowed to install some software or not just by the application of the correct rights, In a domain environment this is of course a lot easier than a peer to peer set up.

Unfortunately due to the developers taking the easy way out with regards to administrative rights with XP there will be some re-thinking required by those tasked with moving to a more secure modern OS. This is quite possible though there will be a learning curve.

The main issue with application installation is not the need for a "super" admin but the "trusted user" used by UAC to protect the Program store. by taking ownership of the role of this "User" most if not all issues may be resolved.

Full information on the Trusted Installer scenario is available from Microsoft on technet - or of course by many independents
 

My Computers My Computers

System One System Two

  • Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    ChillBlast - Custom to my design
    OS
    Windows 11 Pro x64 [Latest Release and Release Preview]
    CPU
    Ryzen 9 5950X, 3.8 - 5.2 MHz
    Motherboard
    Asus Prime X570-Pro
    Memory
    64GB [2 x 32GB] DDR4 3200MHz
    Graphics Card(s)
    4GB NVIDIA GEFORCE GTX 1650 Ti
    Sound Card
    On-board SPDIF to 5.1 System + HDMI [5.1 system]
    Monitor(s) Displays
    32" UHD 32 Bit HDR Monitor + 43" UHD 4K 32Bit HDR TV
    Screen Resolution
    2 x 3840 x 2160 @60Hz
    Hard Drives
    1TB M2 SSD OS, 500GB Fast Access SSD, 2 x 8TB Data + Various Externals from 1TB to 4TB, 10TB NAS
    PSU
    NZXT C750 80 PLUS Gold 750W Modular PSU
    Case
    Workstation Case [Matt Black]
    Cooling
    NZXT Kraken X63 280mm CPU Cooler +2x Quiet Case fans
    Keyboard
    Logitech Wireless MX Keys & K400 + others
    Mouse
    Logitech Wireless MX Master 3S
    Internet Speed
    920 MB Down 50 MB Up
    Antivirus
    BitDefender Total Security Pro
    Browser
    Chrome (always run latest Non-Beta)
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    Samsung 10.2" tablet
    Blackview TAB 8 4G Android Tablet c/w Keyboard
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control
  • Computer type
    Laptop
    System Manufacturer/Model Number
    Dell XPS 17 10750H
    OS
    Windows 11 Pro x64 Latest RP
    CPU
    Intel I7 10750H 5.0GHz
    Motherboard
    Dell XPS
    Memory
    32GB [2x16GB] DDR4 2933 MHz
    Graphics Card(s)
    nVidia GTX1650Ti 4 GB GDDR6
    Sound Card
    Stock [Realtek] 4 Speaker
    Monitor(s) Displays
    17" IPS UHD+ Infinity Edge Touchscreen
    Screen Resolution
    3840 x 2400
    Hard Drives
    2TB M2 NVMe, 4TB External + various 500GB & 1TB External NVMe (also have access to spinner HDD from
    PSU
    Stock
    Case
    Stock XPS Aluminium & Carbon Fibre
    Cooling
    Stock - Active Fan Control
    Keyboard
    Backlit + Various Logitech
    Mouse
    Stock Track Pad + Logitech MX Trackball
    Internet Speed
    72 MB Down 18MB Up
    Browser
    Chrome
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    10.2" tablet
    Sony Z3 Android Smartphone
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control Pad
    10TB NAS
I ran into the same issuse.
Login in to the local administrator account.
Go under Administrative tools,
>Local Users and Groups,
>Groups
and make sure Domain Admin is added to the list of administrators.

Run cmd,
gpupdate /force
That updates all of your group policies.
Log back in as your domain administrator account and see if that works.
 

My Computer My Computer

Computer Manufacturer/Model Number
SMN-Productions
OS
Windows 7 x86/x64, Server 2008r2, Web Server 2008
CPU
i7 v2 3930K Steping stone 2
Motherboard
ASUS Rampage IV Extreme
Memory
G.SKILL Ripjaws Z Series 32GB
Graphics Card(s)
AMD HD 5770
Monitor(s) Displays
Acer 21" and Samsung 20"
Hard Drives
Patriot Pyro 80GB
PSU
1000 Watt
Case
HAF-X
Cooling
4 Fans
Keyboard
Black Widow Ultimate
Domain users' security access control fix

I was very frustrated as well with Windows 7 not allowing any users logged into a domain any administrative access, so I started searching. :mad:

I was unable to find anything resembling "Local Users and Groups" under "Adminisrative Tools". After hacking around for an hour, I was able to finally locate something I saw in another page. They said:

Login in to the local administrator account.
Control Panel
Administrative Tools
>Local Users and Groups (and several steps after that)

Well at that step I was lost because there is NO "Local Users and Groups" in my Administrative Tools, thank you very much. :cry: I finally found "Local Users and Groups" a different way:

Control Panel
Users Accounts
Manage User Accounts
"Advanced" tab
in the "Advanced user mangement" section, click the [Advanced] button
Groups
Administrators
[Add...]
DOMAIN\Domain Users

Of course you put in your domain name where I typed "DOMAIN", and click several buttons, right clicking, and double clicking in many places to follow the bread crumb trail I presented here.

Best of luck making Microsoft security work for you! :cool:
 

My Computer My Computer

Computer Manufacturer/Model Number
Dell Studio 1558
OS
Windows 7 Home Premium 64-bit
CPU
Intel Core i3 M350 2.27GHz
Memory
4.0 GB
The last post's approach fixed the problem for me, so just thought I'd add that the quick way to get to the local users & groups control area is to do:

Start | Run | lusrmgr.msc | enter

Or of course Win+R and lusrmgr.msc

hth,
--
Olly
 

My Computer My Computer

OS
Windows 7 Pro 64bit
Right click on My Computers, Manage, and Local Users and Groups will be listed under "System Tools".

And unless somebody changed something, Domain admins will always be added to the local admin group on workstations when they are joined to the particular domain.
 

My Computer My Computer

Computer Manufacturer/Model Number
Self-Built in July 2009
OS
Windows 7 Ultimate x64
CPU
Intel Q9550 2.83Ghz OC'd to 3.40Ghz
Motherboard
Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS
Memory
8GB G.Skill PI DDR2-800, 4-4-4-12 timings
Graphics Card(s)
EVGA 1280MB Nvidia GeForce GTX570
Sound Card
Realtek ALC899A 8 channel onboard audio
Monitor(s) Displays
23" Acer x233H
Screen Resolution
1920x1080
Hard Drives
Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS
PSU
Corsair 620HX modular
Case
Antec P182
Cooling
stock
Keyboard
ABS M1 Mechanical
Mouse
Logitech G9 Laser Mouse
Internet Speed
15/2 cable modem
Other Info
Windows and Linux enthusiast. Logitech G35 Headset.
Back
Top