Home
Join

1 Reply

  • Alright I figured out a way to deploy without domain admin credentials. I created a GPO called Admin Share access

    Computer Configuration -->Polices --> Windows Settings --> Security Settings --> Local Policies/Security Options -->Accounts  -->Administrator account status -->Enabled

    This step may not be necessary if you know they are enabled in your environment (It just seemed like a good precaution to me)

    Computer Configuration -->Polices --> Windows Settings --> Security Settings -->  Restricted Groups --> Group --> Builtin\ Administrators -->(add your deploy user)

    It didn't really work when I added my deploy user to the Administrators in AD. Since it's a GPO you'll have to wait for replication.

    I also discovered through the joy of getting a text last night that it removes domain admins from the local administrators group. Be sure to add domain admins as well as your deploy user.
    Was this post helpful? thumb_up thumb_down

Read these next...