Orphaned Windows (Domain) machines

The Cobra

2[H]4U
Joined
Jun 19, 2003
Messages
3,182
Hi [H]'ers,

Got a melon scratcher for ya. We let go of an employee last week who was a Jr. Sysadmin at my school (Helpdesk, small admin duties, ext...) All of our new laptops have a local user admin, a domain admin and a Staff group that allows local users to admin their machines. On our older desktops, they were setup with the following: Just a staff security group with no local user at all. He deleted the staff group from AD and now these machines are orphaned in the domain. meaning my master accounts will not do anything with them. (Domain/Ent Admin) Also, there is no way for me to see the local user without having admin rights on the box. So I can't join/unjoin, add other users, install software, ext...

Is there a way for me to add the domain admins groups to each machine from the backend without me having to reimage each machine and add it back into the domain again? This is turning out to be a yuge pain in the ass from an SysAdmin standpoint.

Any help appreciated.
 
You should be able to add an AD group to (or back to) the machine local administrators using Group Policy.
Computer Configuration -> Preferences -> Control Panel Settings -> Local Users and Groups
Add a new local group to update the "Administrators (built-in)" group.. add some members.

Then reboot the machine(s) a few times.
 
That is what I have found. Tried it in the GOP model and came back as working 100% Gonna roll out the GOP on Friday afternoon as I will have around 450 machines that it needs to be pushed too.
 
Back
Top