Solved

Group Membership

Posted on 2011-03-16
14
946 Views
Last Modified: 2012-08-13
So here is a question. Anyone know how to push group membership to users without forcing a restart?  In other words, i have a new security group that i added and have added users to the group however those users still cannot access the folders that group has been given access to.  It seems restarting machines pushes those changes but is their an easier way via command line etc that anyone knows of to force those group changes?  Or is it that the change is supposed to be instant and something is potentially wrong with my AD?

Thanks
0
Comment
Question by:Noduzz
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 5
  • 3
  • +1
14 Comments
 
LVL 7

Expert Comment

by:waleeda
ID: 35151092
no need for restart, because it will check the permissions on the AD, i think you have made the permissions in wrong way. please review you permissions again
0
 
LVL 5

Author Comment

by:Noduzz
ID: 35151166
The permissions are fine.
0
 
LVL 5

Author Comment

by:Noduzz
ID: 35151185
If i add just the user to the folder it works fine,  its only when i have added the user to a group with the same permissions.
0
Office 365 Advanced Training for Admins

Special Offer:  Buy 1 course, get 2nd free!  Buy the 'Managing Office 365 Identities & Requirements' course w/ Accelerated TestPrep, and automatically receive the 'Enabling Office 365 Services' course FREE!

 
LVL 7

Expert Comment

by:waleeda
ID: 35151193
are you sure that you are adding the Group on both sharing permissions and Security Permissions
0
 
LVL 5

Author Comment

by:Noduzz
ID: 35151247
The share has the permission Everyone Full, so yes i am sure.
0
 
LVL 7

Expert Comment

by:waleeda
ID: 35151263
can you add yourself member on this group and try to access the folder and tell me what is the result message you are getting
0
 
LVL 11

Expert Comment

by:BillBondo
ID: 35151354
GP updates itself at a set random time. All your changes should be reflected after that. User and computer settings are in the GP editor under system/group policy folders.
0
 
LVL 3

Expert Comment

by:fireline1082
ID: 35151355

I was searching for this for very very long time and can not find any solution other than restart the machine

So I guess the anwer to your question. no way without restart.

In some cases, you may need to reboot twice as well. Like in my company we are using Mcafee EPO and I have created a security group to give USB and CD room access for the users. I noticed that the currently logged in user's group membership can only referesh after restarting twice. There is a built-in tool in Windows 7 to check the assigned group membership of the user; just from command prompt type: whoami /groups. For XP, you need to download it from microsoft site; just search for Whoami for XP

For testing, create any test group and then assign your self to that group; then run "whoami /groups"; you will see that the test group is not listed until you reboot your machine

I hope we can all find a solution for this !!!! It is a bit annoying thing
0
 
LVL 7

Expert Comment

by:waleeda
ID: 35151363
why gpupdate it's not a grou policy its group membership only :)
0
 
LVL 5

Author Comment

by:Noduzz
ID: 35151633
firline1082, Im glad im not crazy....  It seems though that logging off and logging on the machine may solve the issue as well at least based on the whoami results.  Kinda frustrating.. you would think this issue would have been resolved with windows 7...
0
 
LVL 5

Author Comment

by:Noduzz
ID: 35151653
I mean if you can do a gpupdate to update group policy you would think there would be a similar tool for group membership.
0
 
LVL 7

Expert Comment

by:waleeda
ID: 35154085
for the security permission on another computer or server no need also to log on and log off, but for change permission on the local machine it will require to log on and log off, for applying group policy, i till will require gpupdate /force plus log on and log off if there is a log script or somthing.
0
 
LVL 3

Expert Comment

by:fireline1082
ID: 35155571
Hi Noduzz,

Yes you are right about log off and login (may) solve this problem which it did; but I noticed in my case that I have to do it couple of times and it may not take the group membership quickly and found the restart faster. I am talking about the Mcafee EPO thing

Any how, hope to see some sort of tool that can force the PC to refersh the group membership of the logged-in user without requiring log off or restart (as your wish)

Thanks
0
 
LVL 3

Accepted Solution

by:
fireline1082 earned 500 total points
ID: 35155610
check this old post
http://www.experts-exchange.com/OS/Miscellaneous/Q_22026547.html

this is similar to your question; it is quite old - but was about the same/similar topic

thanks
0

Featured Post

PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question