#131393 - 2004-12-15 11:55 PM
add domain group to local admin while not in domain
|
Radimus
Moderator
   
Registered: 2000-01-06
Posts: 5187
Loc: Tampa, FL
|
hey guys, I am using netdom to add XP machines to the domain (and to rename and move containers), while doing the same for win2k, I could run 'net localgroup administrators /add 'domain\IT Staff"', but XP will not do that... it complains about security trusts.
shell 'netdom join /domain:domain ...' shell 'netdom renamecomputer @wksta ...' shell 'cmd /c net localgroup administrators /domain ...'
Can someone work out a method for this, I figure RUNAS would do it, but haven't been able to work around it.
I will have variables populated already with ladmin & PW and dadmin & PW.
I have the netdom statements working, it is just the localgroup statement that is choking. It needs to run while Ladmin is logged on and not domain member yet.
|
Top
|
|
|
|
#131395 - 2004-12-16 02:40 AM
Re: add domain group to local admin while not in domain
|
Howard Bullock
KiX Supporter
   
Registered: 2000-09-15
Posts: 5809
Loc: Harrisburg, PA USA
|
Have you thought of splitting your script into two pieces?
1) setup a run task and auto logon as domain admin account
2) run NETDOM with /REBoot
Computer reboots and is noW a member of domain
3) auto logon as domain admin (since "Domain Admins group is now in local administrators)
4) finish other tasks
|
Top
|
|
|
|
#131396 - 2004-12-16 04:01 AM
Re: add domain group to local admin while not in domain
|
Radimus
Moderator
   
Registered: 2000-01-06
Posts: 5187
Loc: Tampa, FL
|
wonce netdom join has run, if you look in usermangler, you can see the SID of Dadmin, but it hasn't been resolved... at least until it reboots.
I may try to put it in a runonce, but hopefully runas might do it... unless I can make it more complex with NTDS
|
Top
|
|
|
|
#131399 - 2004-12-16 03:36 PM
Re: add domain group to local admin while not in domain
|
Radimus
Moderator
   
Registered: 2000-01-06
Posts: 5187
Loc: Tampa, FL
|
joining did add the domain admins SID, but I need to add another group and a user... without rebooting if possible
|
Top
|
|
|
|
#131401 - 2004-12-16 03:58 PM
Re: add domain group to local admin while not in domain
|
Radimus
Moderator
   
Registered: 2000-01-06
Posts: 5187
Loc: Tampa, FL
|
|
Top
|
|
|
|
Moderator: Arend_, Allen, Jochen, Radimus, Glenn Barnas, ShaneEP, Ruud van Velsen, Mart
|
0 registered
and 1574 anonymous users online.
|
|
|