Wednesday, April 4, 2018

Windows Server 2016 the Domain Administrator no permissions however, the Local Admin does

I tried to personalize the W2K16 Server desktop by adding desktop icons and I get something like the the error messages below. Sorry no screen shot :-)
C:\Windows\system32\rundll32.exe
Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item.
Note: This does not happen if you login as the local admin. However, if you login as the Domain Admin which is of course a local admin you still get the permissions error.The server was already joined to the domain.

This issue is by design of Windows Server 2016. I knew it was related to server W2K16 so I tracked it down with the help of this article:
https://www.windows-security.org/95e7dc697029b38b45ac53f7efef3935/user-account-control-admin-approval-mode-for-the-built-in


How to fix this issue:
On the Windows 2016 Server open the GPMC, Computer Configuration, Windows Settings, Security Settings, Local Policies,  Security Options, then enable User Account Control: Admin Approval Mode for the Built-in Administrator account
Reboot the server and all is well...

No comments:

Post a Comment