Solved

GPO:  Windows 2008 R2 Local Admin group

Posted on 2014-01-15
7
699 Views
Last Modified: 2014-01-30
Hi All,

I setup a Group Policy around 12 months ago to an AD Group to the local Admins group.  I attached it to our server OU and checked it was working (on a 2003 server).

Recently I noticed it's not applying to any of the 2008 servers.

I followed this guide to the letter

http://www.youtube.com/watch?v=2S8pkW1fZxs

Any ideas?
D
0
Comment
Question by:detox1978
  • 3
  • 2
  • 2
7 Comments
 
LVL 35

Expert Comment

by:Mahesh
ID: 39782606
Not sure why do you require restricted groups GPO on servers ?
Check group policy settings if its applied to authenticated users in security filtering in GPMC?

Run rsop.msc on affected servers and check if GPO is showing there in rsop output as applied?

If its showing as applied,then you must reboot 2008 servers once in order to apply GPO

Please reboot 2008 servers once to test if it's working and also check event viewer on those servers for any errors

Mahesh
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39782614
I beleive you are referring to Restricted Groups? If so Restricted Groups are compatible with 2003 and 2008. On your 2008 server run rsop.msc and check computer and user configuration properties and make sure that the policies are actually being applied.

Restricted Groups

Will.
0
 
LVL 2

Author Comment

by:detox1978
ID: 39782671
Yes it's restricted groups.  

The policy is not showing as being filtered when I run GPRESULT /R

However the setting does not appear in RSOP.msc
0
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39782719
It is filtering out probably due to Security Filtering. Can you check the security filtering and make sure that it is set accordingly.

Will.
0
 
LVL 2

Author Comment

by:detox1978
ID: 39782763
It has the same access as the Default Domain Policy.  It also applies successfully to Windows 2003 Servers

Scope
Delegation
0
 
LVL 2

Author Comment

by:detox1978
ID: 39782781
GPRESULT shows it applying

GP RESULT
0
 
LVL 35

Accepted Solution

by:
Mahesh earned 500 total points
ID: 39782894
It looks like GPO settings are correct

For windows 2008 try GPO preferences to achieve the same results

http://www.grouppolicy.biz/2010/01/how-to-use-group-policy-preferences-to-secure-local-administrator-groups/

Check above article and give try, hopefully it should work

You need to run GPMC console from 2008 \ 2008 R2\ win7 machine in order to view GP preferences

Mahesh
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Learn about cloud computing and its benefits for small business owners.
In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

939 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now