Domain account gets removed from local Administrators group

Mikhail Firsov 1,876 Reputation points
2022-03-30T12:56:31.41+00:00

Hello!

Weird problem: when I add some domain user to the local Administrators group on Windows 10 PRO workstation he/she can be the member of this group for ~1-2 days and then their user accounts gets removed from the Administrators group. It's not the problem of gpo as I've tested it in the test domain without any gpos applied (except the default ones).

???

Thank you in advance,
Michael

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,113 questions
Windows 10 Network
Windows 10 Network
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Network: A group of devices that communicate either wirelessly or via a physical connection.
2,271 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,753 questions
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. MotoX80 31,571 Reputation points
    2022-03-30T13:43:23.857+00:00

    In the local security policy, enable auditing for account management.

    188414-capture.png

    Then check the security eventlog for event id 4733. That will tell you when and who removed the account. You will then need to investigate why that happened.

    188415-capture1.png

    0 comments No comments

  2. Mikhail Firsov 1,876 Reputation points
    2022-03-30T13:53:11.68+00:00

    MotoX80, thank you - I'll do it.

    0 comments No comments

  3. Travis Menninger 1 Reputation point
    2022-09-22T14:34:21.883+00:00

    One of my users is having the same issue. I see where Security ID: System is removing the user from the local admin group. This seems to occur after windows updates. It's happened several time in the last month.

    Now that I see where its happening, how can I prevent this in the future? I don't understand what's causing this to happen.

    243905-error.jpg

    0 comments No comments

  4. Mikhail Firsov 1,876 Reputation points
    2022-09-23T07:26:23.35+00:00

    Hellp all,

    I must apologise for not posting back the results of the testing performed: in my case it was the policy that defines the membership of local administrators group.

    Regards,
    Michael

    0 comments No comments

  5. RoBa 1 Reputation point
    2022-11-18T10:27:04.373+00:00

    Which policy was it?

    0 comments No comments