Restricted Group Policy not working in timely manner

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: boomboom21 (chris.boom_at_qci.com)
Date: 12/09/04


Date: 9 Dec 2004 12:15:54 -0800

We have defined "Domain Admins" as a restricted group in the Default
Domain Policy GPO. The problem is that if we add someone to the
restricted group it can take well over a couple hours for the policy to
remove that user from the group. A normal GPUPDATE will not do
anything, but a "GPUPDATE /FORCE" ran on a DC does work to force the
policy to remove the user from the restricted group. The only
difference between GPUPDATE and GPUPDATE /FORCE (from what I can tell)
is that GPUPDATE only refreshes policies that have changed....and
GPUPDATE /FORCE refreshes all policies regardless of change???

GPO Refresh Frequency has not been modified from default settings. If
I'm correct, this policy should be refreshed on DC's every 5 minutes by
default. I am not seeing any GPO errors in the Event Log. Any ideas
what could be causing this delay?

Thanks



Relevant Pages

  • Re: Adding domain users as local XP administrators...
    ... create the new GPO and set my policy? ... >> create a restricted group policy in the domain policy that will ... >> domain has full rights to the local machine. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Restricted Group Policy not working in timely manner
    ... Security policy is an ... > the GPO has changed. ... > cycle by modifying this policy: ... >> policy to remove the user from the restricted group. ...
    (microsoft.public.windows.group_policy)
  • Re: Restricted Group Policy not working in timely manner
    ... > the GPO has changed. ... > cycle by modifying this policy: ... >> We have defined "Domain Admins" as a restricted group in the Default ... >> GPO Refresh Frequency has not been modified from default settings. ...
    (microsoft.public.windows.group_policy)
  • Re: Group Policy not working
    ... I've had this happen before in our environment, you make changes to the GPO ... and run gpupdate /force and nothing happens. ... install is add the domain user to the administrators group on the local ... sofware will not install if the policy does not apply regardless if it ...
    (microsoft.public.windows.group_policy)
  • Re: Restricted Group Policy not working in timely manner
    ... a GPO will not be processed if it has not changed since the last ... cycle by modifying this policy: ... The problem is that if we add someone to the> restricted group it can take well over a couple hours for the policy to ... A normal GPUPDATE will not do> anything, but a "GPUPDATE /FORCE" ran on a DC does work to force the> policy to remove the user from the restricted group. ...
    (microsoft.public.windows.group_policy)