I noted that it's possible to configure Users and Groups
on servers that do not operate as a DC, but this area is disabled on DCs. I figure that the DOMAIN\Administrator
group is automatically given permissions to log into all DCs.
However, it appears that you can customize the Users and Groups
on servers that do not operate as DCs. Why is this the case? And, why am I unable to add the DOMAIN\Administrators
group to the local Administrators
group on a server that isn't a DC?
Is the new server a clean install or a vm clone? I have read an issue where a user used the same vm-disk to install the dc and a member server. he couldn't add domain users /domain admins to the local admin group.