Looks like a local entry in administrator group is interfering with group policy
on our windows 7 machines not want users logging in administrator access. of course users need able install software on own these users creating 2nd user account ends '00' can used when elevated privileges required. have group policy setup add group called adm_%computername% local administrators group on windows 7 machines. populate groups correct '00' administrator account. used article here accomplish this:
how use group policy preferences secure local administrator groups
it appears work fine machines weird thing happening on machines. thing can find different these machines not working may have had users '00' account entered in local administrator group when policy pushed out. know sounds weird that's difference can find.
on machines not working processes fine, no errors in group policy, no event log messages, adm_%computername% group added local administrators group supposed be. users '00' account verified in adm_%computername% group. time user trys requires administrator privileges enter '00' account , receive error message saying elevated privileges required. if manually enter users '00' account local administrators group works fine.
this has me baffled
leontplatt
nice using post.... off chance... how many security groups '00' accounts members of? if members of many group (200+) might getting token bloat issues.... sometime presents self account not having correct access. thought...
hope helps
alan burchill (mvp)
http://www.grouppolicy.biz
@alanburchill
Windows Server > Group Policy
Comments
Post a Comment