Users have the ability to add themselves to the Domain Admins group, granting them Domain Admin privileges.

Hassan Waheed 10 Reputation points
2025-04-09T12:31:35.4666667+00:00

All users created in Active Directory are able to add themselves to the Domain Admin group, granting themselves Domain Admin privileges.

Users can log into the Domain Controller, access Active Directory, and add themselves to the Domain Admin group.

I tested this issue, removed unnecessary permissions from the Domain Admin group, but upon checking today, all the permissions have been restored.

Can you help me understand why this is happening and how to resolve it?

Windows Server | Identity and access | Active Directory
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.