Restricted Groups GPO Issue
in our default domain policy, had restricted group control membership of domain admin group. worked great until needed add couple of accounts. accounts kept removing though had added them gpo. so, deleted restricted group default domain policy still removed accounts. @ first, though replication. ran following command on dc.
repadmin.exe /replsum /bysrc /bydest /sort:delta
it shows no errors.
what did wrong? how can fix it?
just 1 additional note trying not officially supported. restricted groups used local groups on servers/workstations.
more here
http://support.microsoft.com/kb/279301
managing membership of domain groups using restricted groups
microsoft not support using restricted groups in scenario. restricted groups client configuration means , cannot used domain groups. restricted groups designed work local groups. domain objects have managed within traditional ad tools. therefore, not plan add or support using restricted groups way manage domain groups.
thanks
mike
http://adisfun.blogspot.com
follow @mekline
Windows Server > Group Policy
Comments
Post a Comment