Restricted Groups setting not working.


i've been struggling group policy today, , use advice...

i've been given list of needs happen.

1:  local account administrator must disabled.

2:  create new local account of nw_admin

3:  administrators group needs updated, contain 'domain\sg admins' group , new local administrator.

local admin account disabled - check.

create new local account of nw_admin - check.

i did under computer config -> preferences -> control panel settings -> local users , groups

next, set restricted groups domain group want add.

so in computer config -> policies -> windows settings -> security settings -> restricted groups.

i created new group.  selected domain, , used advanced search feature physically select 'sg admins' group.

i left 'members' section blank.

and in 'this group member of' typed 'builtin\administrators'.

(i've tried variety of caps, lower case , mixed case).

one quick 'gpupdate' later, , through policy.

the local user created , added local admins group.

the built in administrator account disabled.

(that's 2 two!)

but...

the security group not added administrators group.

i used rsop.msc find out what's happening:

(had remove screenshot!  said:)

the policy engine did not attempt configure setting.  more information, see %windir%\security\logs\winlogin.log on target machine.

ok, in winlogin.log file:

----configure group membership...  	configure grantadesign\sg sysads.  	cannot find grantadesign\sg sysads.    	group membership configuration completed 1 or more errors.  

so if i'm reading right, cannot find security group selected manually ad?

this lost , hope can me out here, because don't know how progress this, , should easy config!

i appreciate advice may have.  thank you!

hi,

if i'm not wrong , why don't use same gpp "local users , groups" preferences make domain group member of local administrators on systems using gpo?

the restricted groups setting should work if use "this group domain\your-group member of builtin\administrators , link ou workstations computer accounts reside".

hope helps.

regards,

calin



Windows Server  >  Group Policy



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client