Restricted Groups setting not working.
i've been struggling group policy today, , use advice...
i've been given list of needs happen.
1: local account administrator must disabled.
2: create new local account of nw_admin
3: administrators group needs updated, contain 'domain\sg admins' group , new local administrator.
local admin account disabled - check.
create new local account of nw_admin - check.
i did under computer config -> preferences -> control panel settings -> local users , groups
next, set restricted groups domain group want add.
so in computer config -> policies -> windows settings -> security settings -> restricted groups.
i created new group. selected domain, , used advanced search feature physically select 'sg admins' group.
i left 'members' section blank.
and in 'this group member of' typed 'builtin\administrators'.
(i've tried variety of caps, lower case , mixed case).
one quick 'gpupdate' later, , through policy.
the local user created , added local admins group.
the built in administrator account disabled.
(that's 2 two!)
but...
the security group not added administrators group.
i used rsop.msc find out what's happening:
(had remove screenshot! said:)
the policy engine did not attempt configure setting. more information, see %windir%\security\logs\winlogin.log on target machine.
ok, in winlogin.log file:
----configure group membership... configure grantadesign\sg sysads. cannot find grantadesign\sg sysads. group membership configuration completed 1 or more errors.
so if i'm reading right, cannot find security group selected manually ad?
this lost , hope can me out here, because don't know how progress this, , should easy config!
i appreciate advice may have. thank you!
hi,
if i'm not wrong , why don't use same gpp "local users , groups" preferences make domain group member of local administrators on systems using gpo?
the restricted groups setting should work if use "this group domain\your-group member of builtin\administrators , link ou workstations computer accounts reside".
hope helps.
regards,
calin
Windows Server > Group Policy
Comments
Post a Comment