Solved

Cannot remove members from AD group.

Posted on 2010-11-24
6
1,762 Views
1 Endorsement
Last Modified: 2012-08-13
Hi,

In my AD, I am trying to remove a user from the group. E.g. remove "userabc" from group "XYZ" but I got an error
"This is the member's primary group, so the member cannot be reomved. Go to the Member Of tab of the member's property sheet and set another group as primary. You can then remove the member from this group"

What is the implication if I set the primary group of "userabc" to another group?
1
Comment
Question by:Decarn
  • 3
  • 3
6 Comments
 
LVL 3

Expert Comment

by:Patricck
ID: 34203393
A user must be in the group. First you need to assign a primary group for the user, and than you can remove.
0
 

Author Comment

by:Decarn
ID: 34203406
Hi Patricck,

I am trying to understand the impact/ implications if I were to assign the user to another primary group so that I can remove that user from that group. Any problems like permissions etc will be affected?
0
 
LVL 3

Expert Comment

by:Patricck
ID: 34203437
Yes, a group means also group permissions.
Examlple:
When a user is in the administrator group, and you will change his group to user group - it will change his rights - he will not have Admin rights anymore.
0
Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

 

Author Comment

by:Decarn
ID: 34203840
Hi Patrick,

Correct me if I'm wrong:
Suppose "userA" is in group "groupABC" and "groupXYZ".
"groupABC" is his primary group.
I now set his primary group to "groupXYZ" and remove "userA" from "groupABC". So now he will no longer have access to files, folders and service for "groupABC".

What is the purpose of the primary group?
0
 
LVL 3

Accepted Solution

by:
Patricck earned 500 total points
ID: 34203974
It should be like you say in the AD environment.

http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/39869/view/topic/Default.aspx

"IMHO the primary group (as found on users, security descriptors, etc.)
is of no special consequence for Windows, and is a vestige of POSIX
influences on early NT. But I would not begrudge anyone proving me
wrong. "
1
 

Author Closing Comment

by:Decarn
ID: 34244955
Thanks got it.
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question