Solved

Cannot remove members from AD group.

Posted on 2010-11-24
6
1,785 Views
1 Endorsement
Last Modified: 2012-08-13
Hi,

In my AD, I am trying to remove a user from the group. E.g. remove "userabc" from group "XYZ" but I got an error
"This is the member's primary group, so the member cannot be reomved. Go to the Member Of tab of the member's property sheet and set another group as primary. You can then remove the member from this group"

What is the implication if I set the primary group of "userabc" to another group?
1
Comment
Question by:Decarn
  • 3
  • 3
6 Comments
 
LVL 3

Expert Comment

by:Patricck
ID: 34203393
A user must be in the group. First you need to assign a primary group for the user, and than you can remove.
0
 

Author Comment

by:Decarn
ID: 34203406
Hi Patricck,

I am trying to understand the impact/ implications if I were to assign the user to another primary group so that I can remove that user from that group. Any problems like permissions etc will be affected?
0
 
LVL 3

Expert Comment

by:Patricck
ID: 34203437
Yes, a group means also group permissions.
Examlple:
When a user is in the administrator group, and you will change his group to user group - it will change his rights - he will not have Admin rights anymore.
0
Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

 

Author Comment

by:Decarn
ID: 34203840
Hi Patrick,

Correct me if I'm wrong:
Suppose "userA" is in group "groupABC" and "groupXYZ".
"groupABC" is his primary group.
I now set his primary group to "groupXYZ" and remove "userA" from "groupABC". So now he will no longer have access to files, folders and service for "groupABC".

What is the purpose of the primary group?
0
 
LVL 3

Accepted Solution

by:
Patricck earned 500 total points
ID: 34203974
It should be like you say in the AD environment.

http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/39869/view/topic/Default.aspx

"IMHO the primary group (as found on users, security descriptors, etc.)
is of no special consequence for Windows, and is a vestige of POSIX
influences on early NT. But I would not begrudge anyone proving me
wrong. "
1
 

Author Closing Comment

by:Decarn
ID: 34244955
Thanks got it.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
what is the performance monitor? How can we use it? 3 82
Backup DHCP Server 8 127
Active Directory delegation of control to a user 3 138
Raising Forest Functional Level 9 57
Scenerio: You have a server running Server 2003 and have applied a retail pack of Terminal Server Licenses.  You want to change servers or your server has crashed and you need to reapply the Terminal Server Licenses. When you enter the 16-digit lic…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question