Couldn't access member attribute of "Domain Computers" even if full control is present

Esakki Selvaraj 0 Reputation points
2024-05-21T12:54:48.98+00:00

The member attribute data cannot be fetched using the administrator credential for the group "Domain Computers/Users". The credential has full control access to this group.

Any specific access needs to be provided to get the members of this group? Tested the same using the LDP tool which shows the same result.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,018 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Daisy Zhou 19,586 Reputation points Microsoft Vendor
    2024-05-21T13:59:43.83+00:00

    Hello Esakki Selvaraj,

    Thank you for posting in Q&A forum.

    You can check this Administrator's permission on this group via right clicking this group, then click Security tab\click Advanced button\Effective Access:

    User/Group: type or select Administrator
    click View effective access.

    If there is Read members and Write members permissions.

    User's image

    User's image

    And check if you can see any Deny entry (all entries are Allow below) under Type as below. If there is any deny entry, then check if it is related to this administrator (deny read members).

    User's image

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.