Extra users and groups on in the local admin group on the servers from what configured through restricted group policy
we have group policy configured restricted groups on our servers ou. there sub-ou under servers ou. when checked 1 of servers in sub-ou under servers ou, see many users , groups added in local administrator group on server not coming through restricted group policy. these users , groups not being removed local admin after time ( after policy refresh).
examine properties of sub-ou; inheritance blocked?
the gpo containing rg settings appear in list of linked/inherited gpos?
examine event log of target server; gp processing correctly without errors?
you may wish ask further assistance in dedicated gp forum:
https://social.technet.microsoft.com/forums/en-us/home?forum=winservergp
don [doesn't work msft, , they're glad ;]
Windows Server > Directory Services
Comments
Post a Comment