?
Solved

GPO:  Windows 2008 R2 Local Admin group

Posted on 2014-01-15
7
Medium Priority
?
707 Views
Last Modified: 2014-01-30
Hi All,

I setup a Group Policy around 12 months ago to an AD Group to the local Admins group.  I attached it to our server OU and checked it was working (on a 2003 server).

Recently I noticed it's not applying to any of the 2008 servers.

I followed this guide to the letter

http://www.youtube.com/watch?v=2S8pkW1fZxs

Any ideas?
D
0
Comment
Question by:detox1978
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
7 Comments
 
LVL 37

Expert Comment

by:Mahesh
ID: 39782606
Not sure why do you require restricted groups GPO on servers ?
Check group policy settings if its applied to authenticated users in security filtering in GPMC?

Run rsop.msc on affected servers and check if GPO is showing there in rsop output as applied?

If its showing as applied,then you must reboot 2008 servers once in order to apply GPO

Please reboot 2008 servers once to test if it's working and also check event viewer on those servers for any errors

Mahesh
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39782614
I beleive you are referring to Restricted Groups? If so Restricted Groups are compatible with 2003 and 2008. On your 2008 server run rsop.msc and check computer and user configuration properties and make sure that the policies are actually being applied.

Restricted Groups

Will.
0
 
LVL 2

Author Comment

by:detox1978
ID: 39782671
Yes it's restricted groups.  

The policy is not showing as being filtered when I run GPRESULT /R

However the setting does not appear in RSOP.msc
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39782719
It is filtering out probably due to Security Filtering. Can you check the security filtering and make sure that it is set accordingly.

Will.
0
 
LVL 2

Author Comment

by:detox1978
ID: 39782763
It has the same access as the Default Domain Policy.  It also applies successfully to Windows 2003 Servers

Scope
Delegation
0
 
LVL 2

Author Comment

by:detox1978
ID: 39782781
GPRESULT shows it applying

GP RESULT
0
 
LVL 37

Accepted Solution

by:
Mahesh earned 1500 total points
ID: 39782894
It looks like GPO settings are correct

For windows 2008 try GPO preferences to achieve the same results

http://www.grouppolicy.biz/2010/01/how-to-use-group-policy-preferences-to-secure-local-administrator-groups/

Check above article and give try, hopefully it should work

You need to run GPMC console from 2008 \ 2008 R2\ win7 machine in order to view GP preferences

Mahesh
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Suggested Courses

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question