Forum Discussion
Why is an AAD DC Administrator not a Domain Admin?
- Jun 02, 2021
If I recall correctly there should be a standard GPO in the AADDS domain that adds the AAD DC Admin group to the local admins of a sessionhost. It's applied on the AADDC Computers OU so perhaps you moved your VM's to another OU? Try applying that GPO there as well.
I believe it's called "AADDC Computers GPO" but I'm not sure!
https://docs.microsoft.com/en-us/azure/active-directory-domain-services/faqs#do-i-have-domain-administrator-privileges-for-the-managed-domain-provided-by-azure-ad-domain-services-
- David SchragJun 02, 2021Iron ContributorThat's interesting. So how do you perform administrative functions on the session hosts -- always as the local admin?
- YannickJanssens1986Jun 02, 2021Brass Contributor
If I recall correctly there should be a standard GPO in the AADDS domain that adds the AAD DC Admin group to the local admins of a sessionhost. It's applied on the AADDC Computers OU so perhaps you moved your VM's to another OU? Try applying that GPO there as well.
I believe it's called "AADDC Computers GPO" but I'm not sure!
- Travis_78Feb 01, 2024Iron Contributor
YannickJanssens1986 This helped me out. Thank you! Same issue, using a separate OU and didnt think to link this GPO.