Member of adminstrator group stays as admin even though I removed it. Domain

Ilkin Yusifli 1 Reputation point
2021-03-27T20:06:52.75+00:00

Cant remove admin rights for 1 account that was member of domain admins, and restrticted group (built-in admins), it is not a member of aforementioned groups anymore but this account can install and elevate as admin on domain joined comps in what I used it before. new domain joined comps dont recognize him as admin and asks for elevation. Is it some sort of cache or what else? confused(

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Client for IT Pros | User experience | Other
{count} votes

2 answers

Sort by: Most helpful
  1. Anonymous
    2021-03-27T21:39:53.877+00:00

    Might clear out Control Panel\User Accounts\Credential Manager

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  2. Anonymous
    2021-03-29T02:28:22.803+00:00

    Hi,
    Try to confirm if the admincount attribute of the user is still remain one, is yes ,change it back to zero .
    When a user / group is removed from a protected group, adminCount attribute value will remain equal to one (1). Also; the owner, ACLs and permission inheritance status (Enabled or Disabled) will remain the same. Change it manually.
    Logout and login in again to refresh the group membership.

    Best Regards,

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.