AdminCount, SDProp and AdminSDHolder
Started a new job recently and discovered the wonderful world of AdminCount, SDProp and AdminSDHolder as per subject.
My user account kept on being removed from the Domain Admins security group and I instantly knew what the problem was....Restricted Groups. How wrong I was. After some days, I discovered the AdminSDHolder OU.
Long story short, how do I go about adding myself to this "process" so that my user account does not get removed?
I found this Microsoft article useless and saw many YT videos showing how to "hack" this process by merely adding the user account to the ACL (or the security tab of the OU) but this is obviously not the correct way to go. Any help appreciated. Btw, I did try to change the ASD attribute called adminCount to 1, to no avail.
Thanks for reading.