Looks like a local entry in administrator group is interfering with group policy


on our windows 7 machines not want users logging in administrator access.  of course users need able install software on own these users creating 2nd user account  ends '00' can used when elevated privileges required.  have group policy setup add group called adm_%computername% local administrators group on windows 7 machines.  populate groups correct '00' administrator account.  used article here accomplish this:

how use group policy preferences secure local administrator groups

http://www.grouppolicy.biz/2010/01/how-to-use-group-policy-preferences-to-secure-local-administrator-groups/  

it appears work fine machines weird thing happening on machines.  thing can find different these machines not working may have had users '00' account entered in local administrator group when policy pushed out. know sounds weird that's difference can find.

 

on machines not working processes fine, no errors in group policy, no event log messages, adm_%computername% group added local administrators group supposed be. users '00' account verified in adm_%computername% group. time user trys requires administrator privileges enter '00' account , receive error message saying elevated privileges required.  if manually enter users '00' account local administrators group works fine.

 

this has me baffled



leontplatt

nice using post.... off chance... how many security groups '00' accounts members of? if members of many group (200+) might getting token bloat issues.... sometime presents self account not having correct access. thought...

hope helps


alan burchill (mvp)
http://www.grouppolicy.biz

@alanburchill



Windows Server  >  Group Policy



Comments

Popular posts from this blog

Motherboard replacement

Cannot create Full Text Search catalog after upgrading to V12 - Database is not fully started up or it is not in an ONLINE state

Remote Desktop App - Error 0x207 or 0x607