Restricted Groups GPO Issue


in our default domain policy, had restricted group control membership of domain admin group. worked great until needed add couple of accounts. accounts kept removing though had added them gpo. so, deleted restricted group default domain policy still removed accounts. @ first, though replication. ran following command on dc.

repadmin.exe /replsum /bysrc /bydest /sort:delta

it shows no errors.

what did wrong? how can fix it?

just 1 additional note trying not officially supported.  restricted groups used local groups on servers/workstations.

 

more here

http://support.microsoft.com/kb/279301

managing membership of domain groups using restricted groups

microsoft not support using restricted groups in scenario. restricted groups client configuration means , cannot used domain groups. restricted groups designed work local groups. domain objects have managed within traditional ad tools. therefore, not plan add or support using restricted groups way manage domain groups.

thanks

 

mike


http://adisfun.blogspot.com
follow @mekline


Windows Server  >  Group Policy



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2