Forum Discussion

David Schrag's avatar
David Schrag
Iron Contributor
Jun 01, 2021

Why is an AAD DC Administrator not a Domain Admin?

I couldn't figure out why I was unable to connect to my Win 10 session hosts using the credentials I used to join the session hosts to the domain during deployment.   I see now that this account, w...
  • YannickJanssens1986's avatar
    YannickJanssens1986
    Jun 02, 2021

    David Schrag 

    If I recall correctly there should be a standard GPO in the AADDS domain that adds the AAD DC Admin group to the local admins of a sessionhost.  It's applied on the AADDC Computers OU so perhaps you moved your VM's to another OU? Try applying that GPO there as well.

     

     I believe it's called "AADDC Computers GPO" but I'm not sure!

     

Resources