Re: Group policy tatooing with restricted group ? or strange behaviour !




Hello Eric,

Run after the 3rd change when the user is logged in rsop and check if the policy is apllied with the correct setting.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Thank you for your answer but perhaps I was not clear enough.

There is no policy change when the problem occured. The user is
retrieving an OLD group policy when it is not connected to the LAN.

If the user added his account during Configuration 2; then, even if
the configuration 3 deleted the user account that was in the admin
group; if the user unplugged the network and reboot, his old user
account (in configuration 2) is present in the local admin group.

I hope I am clear enough this time :)

thanks

Hello Eric,

If the policy change is not applied because the machine was not on
the domain when you made the change, this is normal. To apply the new
policy the machine has to be connected toi the domain.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
Hello,

we have Windows 2000/Xp clients in our Active Directory.

Configuration 1 --> We had a GPO applied on computers that defined a
restricted group for BUILTIN\Administrators. (So, if a user wanted
to add himself to his local administrators group,his user account
was automatically removed from this group).

Configuration 2 --> During three months, we have changed this GPO
and the restricted group was defined witht the "member of" parameter
so a user was able to add himself to the local admin group.

Configuration 3 (= configuration 1) --> Then, as some of the users
knew the local admin password and have added without autorization to
the local admin group, we have configured the restricted group as
before (and so users are removed from the local admin group).

now the problem ...

If a user power on his computer with the network disabled or if the
GPO is not applied for any reason), the local admin group is
identical to what is was during the "configuration 2" and so some
users are local admin ...

Is it normal ?

Thank you



.



Relevant Pages

  • Re: Group policy tatooing with restricted group ? or strange behaviour !
    ... If the user added his account during Configuration 2; then, even if the configuration 3 deleted the user account that was in the admin group; if the user unplugged the network and reboot, his old user account is present in the local admin group. ... If the policy change is not applied because the machine was not on the domain when you made the change, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Group policy tatooing with restricted group ? or strange behaviour !
    ... If the policy change is not applied because the machine was not on the domain when you made the change, ... Configuration 2 --> During three months, we have changed this GPO and ... user was able to add himself to the local admin group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Group policy tatooing with restricted group ? or strange behaviour !
    ... I agree but my question is "how can I define the "default" users that have to be member of the local admin group when the computer is not connected on the network and so the group policy is not applied? ... Configuration 2 --> During three months, we have changed this GPO and the restricted group was defined witht the "member of" parameter so a user was able to add himself to the local admin group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: 2003 Server GPO disabling Bridged Networking
    ... If a policy is configured and linked to the OU where the user or computer object is located it should be applied, check with RSOP on the client or gpresult /v. ... Don't make your users local admin. ... Configuration, Administrative Templates, Network, and Network ...
    (microsoft.public.windows.server.general)
  • Re: SBS2003 Client Setup Wizard Problem
    ... I WAS NOT happy with adding users to the local admin group even for first ... they will ask for User Account Control for permission to connect to the domain. ... this user will be added to local admin user group on the client computers. ...
    (microsoft.public.windows.server.sbs)

Loading