Score:0

How can I enable BUILTIN\Administrators for my user

hm flag

I am working in an Windows active directory environment.

I am connected to a windows workstation with a domain user.

Here is what I see when I type:

whoami /groups

BUILTIN\Administrators      Alias     S-XXXXX              Group used for deny only  
         

I have a local administrator account too and a domain administrator account. I have tried to add my user to this group. I have also tried to remove it from the group and add it again (with "net localgroup groupname username /add") command.

It does not work. My user is still present in this "Deny" group.

How can I add my user to Administrators group ?

Thanks

cn flag
The "deny" is part of User Account Control. You can read up on it here: https://learn.microsoft.com/en-us/windows/security/application-security/application-control/user-account-control/how-it-works
Bob5421 avatar
hm flag
UAC works with access tokens ? I do not understand why groups are involved...
Keith Langmead avatar
us flag
Looks like you may be seeing the "deny only" comment due to how you're viewing `whoami`, not a permissions thing as such. See https://blogs.infosupport.com/uac-and-tokens/ which matches what I see, eg if I run `whoami /groups` from an elevated cmd prompt I get "Mandatory Group, Enabled by default, Enabled group" instead of "Group used for deny only".
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.