Global Admin account lacks permissions to do anything on VM

Andrew K 101 Reputation points
2020-01-29T16:46:02.527+00:00

I've set up the an Azure AD and AADDS along with a VM following the guides provided by Microsoft on the forums.

I'm trying to have an account 'Admin' be able to edit/create GPO's and User information on the Active Directory Administrative Centre on the VM (2016). On the Azure Portal the account has the 'Global Admin' Rights but when logged into the VM it's like the Account has next to no permissions.

The Account is in Domain Users and the group that gets created with the ADDS Admin group. I think in order to have the account be able to do the changes it needs to be in the Domain Admin group, but the account doesn't have the permissions to change that.

So, Is it possible to have that and/or How would it be done?

When i log onto the VM with the account and go into Active Directory Administrative Centre -> User 'Admin' -> Member Of -> Add -> "AADDS Service Administrators Group" It throws out and Error Of "Failed to save "Admin". "Failed to save the group membership for the object. Could not add member(s) to one or more ADGroup."

If i try to add the account "Admin" to 'Domain Admins' Via Powershell (Admin) it says that the account im using (Which is the account im trying to add to the domain admins) Doesn't have the right access to do that command and it will be processed at the domain Controller.

The Account is apart of the Local Administrators group, Along with the Domain Users and the AAD DC Administrators Group.

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,105 questions
Microsoft Entra
0 comments No comments
{count} votes

Accepted answer
  1. Andrew K 101 Reputation points
    2020-02-21T11:08:16.757+00:00

    In the End, i managed to get in contact to support through email who told me that there was no way for this to be achieved as the "Domain Admins Group" was a group managed by microsoft themselves.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 33,801 Reputation points Microsoft Employee
    2020-01-30T00:54:06.09+00:00