AdminCount, SDProp and AdminSDHolder

fnanfne 1 Reputation point
2022-12-12T10:51:01.433+00:00

Started a new job recently and discovered the wonderful world of AdminCount, SDProp and AdminSDHolder as per subject.

My user account kept on being removed from the Domain Admins security group and I instantly knew what the problem was....Restricted Groups. How wrong I was. After some days, I discovered the AdminSDHolder OU.

Long story short, how do I go about adding myself to this "process" so that my user account does not get removed?

I found this Microsoft article useless and saw many YT videos showing how to "hack" this process by merely adding the user account to the ACL (or the security tab of the OU) but this is obviously not the correct way to go. Any help appreciated. Btw, I did try to change the ASD attribute called adminCount to 1, to no avail.

Thanks for reading.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,726 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,958 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.