Re: Computer Account Group Membership



I don't know how waiting seven days is going to help as far as I know the
machine has authenticated to the domain and until it re-authenticates
(Reboot) I don't see how it can change its group membership token. The only
way I am aware of is a reboot.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"BenP" <BenP@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:90BB3F45-59FC-46AF-B57F-FF83C37B39CC@xxxxxxxxxxxxxxxx
I am using computer account 'filter' groups to apply policy.

I add a computer account to the the group. I then have to reboot or wait 7
days (renewable kerberos tickets) for the membership and policy to apply.

How can I force this to happen without rebooting, I have tried variations
of
purging kerberos tickets and nltest and netdom to reset the secure channel
or
cycle the password but this doesnt seem to do it.

Rgds


.



Relevant Pages

  • Re: Computer Account Group Membership
    ... Paul Bergson ... I dont want to wait and can't reboot so is there any way of forcing this ... I don't see how it can change its group membership token. ... days (renewable kerberos tickets) for the membership and policy to ...
    (microsoft.public.windows.server.active_directory)
  • Re: Computer Account Group Membership
    ... 2003, 2000 (Early Achiever), NT ... Please no e-mails, any questions should be posted in the NewsGroup ... I dont want to wait and can't reboot so is there any way of forcing this ... days (renewable kerberos tickets) for the membership and policy to ...
    (microsoft.public.windows.server.active_directory)
  • Re: Computer Account Group Membership
    ... I have proven that I can just leave the machine and after 7 days the policy ... I dont want to wait and can't reboot so is there any way of forcing this ... I don't see how it can change its group membership token. ... days (renewable kerberos tickets) for the membership and policy to apply. ...
    (microsoft.public.windows.server.active_directory)
  • ldap client will not shutdown
    ... my laptop won't reboot, ... hangs somewhere in the shutdown process and waiting for over an hour does ...
    (Debian-User)
  • Screwed up USB
    ... user has just pulled a usb drive out before waiting for it to finish transfering data. ... I killed all processes that have an open file descriptor to the directory the ... The user would rather I not reboot as the machine is running a model that's been number-crunching for days. ...
    (Debian-User)

Loading