Solved

Group Policy Not Seeing Correct Group Memberships

Posted on 2011-02-15
2
433 Views
Last Modified: 2012-05-11
I have created a new group policy on my Win2K3 DC so that I have a separate Windows Update policy for servers and workstations.  I have restricted the server GP to only members of the Domain Servers security group.  I have confirmed that all servers are members of this group in AD.  However, I have one server that is not picking up the new policy.  When I run Group Policy Results, the new Windows Update policy is shown as Denied, with the reason as 'Inaccessible'.  When I look at the Security Group Membership when Group Policy Applied, the Domain Servers group is not listed.  The problem server is a Win2K3 VM running under Virtual Server 2005.  However, I have other VM's running both under VS and Hyper-V that don't have this problem.  Any help is appreciated.
0
Comment
Question by:jduehmig1
2 Comments
 
LVL 83

Accepted Solution

by:
oBdA earned 500 total points
ID: 34904210
"Domain Servers" is not a default group, so you have to add that machine manually to the group. The group membership change requires a reboot of the machine before it will be recognized.
0
 

Author Closing Comment

by:jduehmig1
ID: 34915755
The answer seems to be that either a reboot or waiting several days for the membershp changes to be picked up by the individual servers.  I made the GP and security group changes on Thursday and the last server picked up the changes the following Wednesday.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Installing a printer using group policy preferences is not that hard let’s take a look at it. First lets open up your group policy console and edit the policy you want to add it to. I recommend creating a new policy for each printer makes it a l…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now