SOLVED

Domain Admin does not have admin privileges on domain Win10 workstation

%3CLINGO-SUB%20id%3D%22lingo-sub-2612839%22%20slang%3D%22en-US%22%3EDomain%20Admin%20does%20not%20have%20admin%20privileges%20on%20domain%20Win10%20workstation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2612839%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSTRONG%3EDomain%20Admin%20does%20not%20have%20admin%20privileges%20on%20domain%20Win10%20workstation%3A%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EEnvironment%3C%2FSTRONG%3E%3A%3C%2FP%3E%3CP%3EDC%2FAD%3A%20Windows%20Server%202016%3C%2FP%3E%3CP%3EWorkstation%3A%20Windows%2010%20Enterprise%202OH2%2019042.1110%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EIssue%3C%2FSTRONG%3E%3A%3C%2FP%3E%3CP%3EAs%20a%20member%20of%20the%20%22Domain%20Admins%22%20and%20%22Administrators%22%20groups%2C%20a%20user%20%22sean%22%20is%20denied%20elevated%20privileges%20on%20a%20Windows%2010%20machine%2C%20and%20it%20is%20continually%20prompted%20for%20elevated%20admin%20rights.%20This%20issue%20began%20after%20this%20new%20domain%20admin%20user%20was%20created%20and%20logged%20on%20to%20this%20machine%20for%20the%20first%20time.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECMD%20%22%3CEM%3Ewhoami%20%2Fgroups%3C%2FEM%3E%22%20does%20not%20show%20inherited%20domain%20admin%20groups%2C%20however%2C%20CMD%20%22%3CEM%3Enet%20user%20sean%20%2Fdomain%20%7C%20find%20'group'%3C%2FEM%3E%22%20does%20show%20user%20%22sean%22%20as%20a%20member%20of%20the%20%22Administrators%22%20and%20%22Domain%20Admin%22%20groups.%3C%2FP%3E%3CP%3EScreenshot%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Screenshot%202021-08-03%20181657.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F300601iAAA339F9AF715224%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Screenshot%202021-08-03%20181657.png%22%20alt%3D%22Screenshot%202021-08-03%20181657.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EIssue%20Isolation%3C%2FSTRONG%3E%3A%3C%2FP%3E%3CP%3E-%20If%20the%20same%20user%20%22Sean%22%20logs%20onto%20another%20Windows%20machine%2C%20the%20user%20has%20elevated%20permissions.%3C%2FP%3E%3CP%3E-%20Other%20domain%20admins%20do%20not%20experience%20this%20issue%20on%20this%20workstation.%3C%2FP%3E%3CP%3E-%20Rebooted%20DC%3C%2FP%3E%3CP%3E-%20Rebooted%20workstation%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20would%20cause%20this%20issue%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2612839%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EActive%20Directory%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
New Contributor

Domain Admin does not have admin privileges on domain Win10 workstation:

 

Environment:

DC/AD: Windows Server 2016

Workstation: Windows 10 Enterprise 2OH2 19042.1110

 

Issue:

As a member of the "Domain Admins" and "Administrators" groups, a user "sean" is denied elevated privileges on a Windows 10 machine, and it is continually prompted for elevated admin rights. This issue began after this new domain admin user was created and logged on to this machine for the first time.

 

CMD "whoami /groups" does not show inherited domain admin groups, however, CMD "net user sean /domain | find 'group'" does show user "sean" as a member of the "Administrators" and "Domain Admin" groups.

Screenshot:

 

Screenshot 2021-08-03 181657.png

 

 

Issue Isolation:

- If the same user "Sean" logs onto another Windows machine, the user has elevated permissions.

- Other domain admins do not experience this issue on this workstation.

- Rebooted DC

- Rebooted workstation

 

What would cause this issue?

 

 

1 Reply
best response confirmed by seanvree (New Contributor)
Solution
For some reason, this resolved itself. Not sure why or how.