Re: restricted groups frustration!

Tech-Archive recommends: Fix windows errors by optimizing your registry



yes i am working on the DC... but why should this matter? and im applying this to the default domain policy. i cant do it at the OU level because there are hundreds of OU's with servers in them.

thanks



"Anthony" <anthony.spam@xxxxxxxxxxxxxx> wrote in message news:uPid7RQBIHA.4656@xxxxxxxxxxxxxxxxxxxxxxx
Are you perhaps working directly on the DC, instead of using the GP console from a workstation?
Also, as Tim said, the policy should apply to a distinct OU where the servers are.
Anthony, http://www.airdesk.co.uk


"Phillip Drummond" <w@xxxxx> wrote in message news:%23VB6cEQBIHA.1208@xxxxxxxxxxxxxxxxxxxxxxx
nope. this isnt working. the ONLY place the group is being added to is the builtin\administrators group in AD (active directory users and computers) NONE of the domain machines are getting this group added.
does anyone have ANY idea what i can check?




"Tim Chin" <donotemail> wrote in message news:%23On0k5PBIHA.1212@xxxxxxxxxxxxxxxxxxxxxxx
It sounds like you're doing everything correct. I would just make sure that when you are in restricted groups, be sure to use the object picker to find the group you want added to the administrators group. Typing 'Administrators' in the second part should work fine. If you perform a gpupdate (no /force or reboot is required), you'll see the changes immediately (if the dc that provided logon has the latest version of the gpo you're working with).

Note: If you're putting this in the default domain policy, it will also apply to domain controllers. If this is not the desired RSOP, you'll most likely want to create a new gpo with these settings in it and security filter it to 'Domain Computers', which avoids domain controllers.

Tim

"Phillip Drummond" <w@xxxxx> wrote in message news:uY9DDJPBIHA.1212@xxxxxxxxxxxxxxxxxxxxxxx
why doesnt this simply work??
i am trying to add an AD group to the local administrators group on all domain servers. i am using the default domain policy, computer configuration, windows settings, security settings, restricted groups.

i create a new group in here using the group that i want added to local admins and then configure the second box "this group is a member of" option. in here i am typing "Administrators".

24 hours has gone by. shouldnt i be able to log on to ANY domain machine and see this group in the local admins group? because i dont. can someone please tell me what the problem is?








.



Relevant Pages

  • Re: restricted groups frustration!
    ... the builtin\administrators group in AD NONE of the domain machines are getting this group added. ... If you're putting this in the default domain policy, it will also apply to domain controllers. ... If this is not the desired RSOP, you'll most likely want to create a new gpo with these settings in it and security filter it to 'Domain Computers', which avoids domain controllers. ... i create a new group in here using the group that i want added to local admins and then configure the second box "this group is a member of" option. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Aftermath of RDIRCMP.EXE?
    ... Why not just make the Default Domain Policy back to default, which wiill eliminate any possibility that anything you change in there will affect the domain adversely. ... Then create the OU, and as Jorge suggested, link the GPO you previously created, or if you haven't created one, create one with the necessary settings. ... Also, just an FYI, there was another thread recently posted with a similar question, including an OU/GPO design question. ...
    (microsoft.public.windows.server.active_directory)
  • Internet Explorer Proxy Settings
    ... Bis vor kurzem waren unsere Proxysettings ueber die Default Domain Policy ... wird mir bei dem lokalen User als ausschlaggebendes Objekt die Default ... Die Settings wurden aber richtig uebernommen... ...
    (microsoft.public.de.german.win2000.gruppen_richtlinien)
  • Re: Default domain policy
    ... None of the default policies specify any permission settings. ... In the Default Domain Policy the only things defined by default are the ... manually or by importing a security template. ...
    (microsoft.public.win2000.group_policy)
  • IE maintentance, Proxy Settings, No override
    ... my question--I made a new topic cuz I wasn't sure if old ... settings doesn't come back in the new GPO)? ... import them into the new default domain policy after ...
    (microsoft.public.windows.group_policy)