Re: How to configure local PC group membership via Group Policy?



OK, update to my last post.

In the 'This group is a member of' section, I select the 'built in' group in
AD corresponding to the local group on the PC, after a restart the policy is
applied to the PC correctly.

However if I look at the group membership of the security group on the
server that was specified as the restricted group (ie TestRG in my example
below), there are no members, even though I did specify in the policy
configuration a member list for this group?

TIA

--
Kind Regards


Shane
SME IT Solutions
Email: mailto:shane@xxxxxxxxxxxx

"Shane@smeIT" <shane@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:OUlYLhLUFHA.228@xxxxxxxxxxxxxxxxxxxxxxx
> Hi Simon
>
> Thanks for your reply. I can't get my head around how this works (or get
> it to work for that matter :(
>
> The server is a W2003 Server, with WXP Clients.
> I create a new GPO and call it say RestrictedGroups.
> I Edit RestrictedGroups (Computer Configuration / Windows Settings /
> Security Settings / Restricted Groups)
> There are three configuration points here;
> First is Add Group (I'm assuming I need to create a security group
> for this purpose first and browse to it here)
> So let's just say I created a security group called TestRG, and
> have browsed to and selected it here
> Next is members of this group
> Again I can browse to a Domain based security group or user and add
> them in here
> Finally 'This group is a member of'
> I can only browse to Domain based groups here, not local groups?
>
> What I want to be able to do is make a Domain level Security Group a
> member of a Local Built In Windows XP Security Group on a selection of
> Windows XP computers (based on OU membership) from the server via Group
> Policy. From what I have read researching Restricted Groups this seems to
> be the way to do it but I seem to be missing something as it doesn't seem
> to be working. The members and the members of that I am configuring just
> aren't working?
>
> Help..!!
>
> Thanks Simon
>
> --
> Kind Regards
>
>
> Shane
> SME IT Solutions
> Email: mailto:shane@xxxxxxxxxxxx
>
> "Simon Geary" <simon_geary@xxxxxxxxxxx> wrote in message
> news:%23SEb3ZAUFHA.3056@xxxxxxxxxxxxxxxxxxxxxxx
>> You can use restricted groups to do this.
>> http://support.microsoft.com/?id=228496
>>
>> "Shane@smeIT" <shane@xxxxxxxxxxxxxxxxxxxx> wrote in message
>> news:OaY656%23TFHA.2872@xxxxxxxxxxxxxxxxxxxxxxx
>>> Does anyone know how to do this?
>>>
>>>
>>> Basically I want to be able to configure local security group membership
>>> on Windows XP PC's via Group Policy from a Windows 2003 Server.
>>>
>>> TIA
>>>
>>> --
>>> Kind Regards
>>>
>>>
>>> Shane
>>> SME IT Solutions
>>> Email: mailto:shane@xxxxxxxxxxxx
>>>
>>>
>>
>>
>
>


.



Relevant Pages

  • Re: Can not log on locally to any DCs
    ... Last time this happened to me was some stupid Admin that denied a given security group to logon locally, the problem was that security group had another security group as member, so any member of these security groups stopped to logon locally on the server. ... also check the "Deny logon locally" user right in the Default Domain Controllers GPO. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Remote Desktop Admin, Trusted Domain
    ... When You Try to Log on to a Terminal Server ... domain A. This server is located in site 1 along with a Windows ... the 2003 member server cannot see the ... Members of domain B are held in a security group in domain A. ...
    (microsoft.public.windows.terminal_services)
  • Re: Group Policy Wont Apply Unless User is a Member of Domain Admin. Why?
    ... the security group that my test user is a member of. ... you wrote added by default when I created the gpo. ... gpo will only apply if the test user (uTest) is a member of theDomain> Adminssecurity group. ...
    (microsoft.public.windows.server.sbs)
  • Re: Automatically adding computers to a group
    ... their domain computer account password expires. ... security group every time its joined to a domain. ... Interesting concept, "run once GPO. ... that all machines are a member of. ...
    (microsoft.public.windows.server.active_directory)
  • GP/OU Problem/Question
    ... DC and a separate Windows 2003 member server as the TS. ... Create OU & GPO for the TS: ... Make the Security group member of RDU. ... Edit GPO & Setup Edit for test: ...
    (microsoft.public.windows.terminal_services)