User privilege caching in Active Directory?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hello!
I have an Active Directory domain and a web application (that is
developed with .Net and runs on the domain controller) which manages
users' group membership.
I have configured the privileges associatetd with these custom groups.
When I change a user's group membership, the new privileges
(associated to the new group profiling of the user) are not applied
immediately.
It looks like there is a kind of caching of the privileges: I see that
the user belongs to the new groups, but he can't do the right
operations he is supposed to do (because of his membership to certain
groups).
After a certain delay (10-12 minutes) the user privileges are
correctly set.
It is not just a problem of propagation to the computers of the
domain: I'm also talking about privileges on the Active Directory
itself (i.e. privilege to create users in a certain ou, etc.)
I've tried to refresh the cache on the DirectoryEntry object, but
nothing changed.
If there is such a caching (and I cannot force the refresh) I would
like to disable it.
I have tried to modify the registry keys under HKEY_LOCAL_MACHINE
\Software\Microsoft\DRMS\1.0\DirectoryServices, but nothing changed...
Any suggestion would be greatly apreciated!
Thankyou!
Filippo
.



Relevant Pages

  • Roles Engineering for Active Directory
    ... Automatic Roles Engineering for Active Directory ... We have developed a unique technology that enables reverse engineering of ... the existing access rights and data stored in Active Directory into Logical ... Any insert change or delete in users' privileges. ...
    (comp.os.ms-windows.nt.admin.security)
  • Re: Windows Integrated Security - Restricting Users Without Groups
    ... application when those permissions are not taken into account. ... it seems that the windows group membership does not correlate to ... >>> users are in fact, Active Directory user accounts, or whether, perhaps, ... >>> database, which would be entirely separate from Active Directory, other ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Getting Group Membership
    ... > Lagash Systems S.A. ... > Before, I had queried active directory, got the list of groups for the user ... > 'is a domain admin ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Security groups in Active directory not applying after de promoting a domain controller
    ... given it time to update the settings. ... > the group membership?? ... > Free Windows event logs reports ... >> in active directory and add members to that group. ...
    (microsoft.public.win2000.active_directory)
  • Re: Can administrator privileges be limited
    ... account and give it a *few* special rights to do certain things. ... Active Directory has greatly improved on this and made it a lot ... > If the privileges are limited, how does the admin get them back? ... > I have seen several postings that say they are using Admin but don't> have the privileges to install software or add a printer. ...
    (microsoft.public.windowsxp.security_admin)