Re: Add another domain user group to local administrators of all computers in an OU with removing others?
- From: Meinolf Weber <meiweb(nospam)@gmx.de>
- Date: Tue, 22 Jul 2008 16:07:38 +0000 (UTC)
Hello rosevilleca@xxxxxxxxx,
By default, Group Policy refreshes in the background every 90 minutes, with a random offset of 0 to 30 minutes.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
On Jul 21, 1:46 pm, "Paul Bergson [MVP-DS]"
<pbergson@xxxxxxxxxxxxxxxxx> wrote:
You are confused.So, "is a member of" was the clarification needed to get it to work
If you go through the info I provided and apply as stated, it will
add additional groups to thelocaladmins, just make sure to select
"This Group is a member of" not "Members of this Group".
--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
the way I was describing.
So, now it works without removing other admins, but the new problem is
that it isn't enforced if someone goes in and deletes the group from
the local adminstrators on a machine.
We have set "always wait for network" when logging on so the GPOs take
effect without taking 2 reboots, but after deleting the group from the
local administrators on a machine, the group was not re-added to local
administrators when the machine is rebooted. We even tried rebooting
twice with no luck.
The only way the group reappeared as a local admin was by running
gpupdate -- and not just gpudate, but gpupdate -force. After using
the force switch, the group was re-added to the local admins.
Is there any way around this, or will it eventually automatically add
the group back to local administrators without needing to run the
gpupdate /force command if we just wait longer?
.
- Follow-Ups:
- References:
- Prev by Date: Re: Add another domain user group to local administrators of all computers in an OU with removing others?
- Next by Date: Re: 2k to 2k3
- Previous by thread: Re: Add another domain user group to local administrators of all computers in an OU with removing others?
- Next by thread: Re: Add another domain user group to local administrators of all computers in an OU with removing others?
- Index(es):
Relevant Pages
|