Domain Administrator does not have Local Administrator Privileges on New DC Server

Karl Burrows 1 Reputation point
2021-12-18T07:11:55.64+00:00

Just migrated from a 2012R2 DC Server to a 2019. The migration went pretty smoothly and there are no errors in DCDIAG. The Domain Administrator account on the new server does not have local administrator privileges. I can't even reboot the server without using CTRL + ALT + DEL to do it from task manager. Other issues are installing and changing printers, etc. Everything has to be run with elevated privileges or I can't run it at all (like installing new printer drivers). It's the only issue I am having with the new server. I tried creating a Local Admins GPO and that didn't change anything. Scratching my head on this one!

Thanks!

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

15 answers

Sort by: Most helpful
  1. Anonymous
    2021-12-18T14:52:34.82+00:00

    Not sure what is meant. If the new server is a domain controller then there are no local accounts.

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

  2. Karl Burrows 1 Reputation point
    2021-12-18T16:49:17.987+00:00

    I understand that, but it acts like it doesn't have any local privileges. It can't do anything without run as admin or it's grayed out and not available at all. I can't even reboot the computer from the start menu. I have to use CTRL + ALT + DEL. I have to run command prompt as administrator to even run ipconfig or dcdiag without getting an error or incomplete info.

    0 comments No comments

  3. Anonymous
    2021-12-18T16:58:41.85+00:00

    Might check this one is Enabled

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    158677-image.png

    0 comments No comments

  4. Karl Burrows 1 Reputation point
    2021-12-18T17:03:53.66+00:00

    Yes, it's enabled. I think I tried every iteration of modifying local policies (which I also have to run as administrator to edit) and nothing. I have tried different GPO settings, etc. and nothing seems to stick. I had a similar issue with another Server 2019 migration earlier this year but only minimal issues that didn't interfere with running most of the server functions.


  5. Karl Burrows 1 Reputation point
    2021-12-18T18:10:01.05+00:00

    Yes, everything migrated correctly including FRS to DFRS. DCDIAG shows everything is healthy. Everything you mentioned above has already been completed. The new DC is fully functional.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.