Solved

"Allow logon locally" - User Rights Assignment - applied, but not taking effect

Posted on 2014-11-12
6
54 Views
Last Modified: 2015-06-28
Hi,

I've recently set a new GPO to restrict the 'Allow logon locally' to Administrators, Power Users and Backup Operators.

Resultant Set of Policy shows this policy applies without a problem:

2.JPG
Yet when I launch gpedit.msc on the machine, it shows the following:

1.JPG
The policy seems to be applying, but not taking effect. The settings above are locked and I cannot manually modify them.

Does anyone have any idea why this is happening? Restarting the computer, running gpupdate /force, setting the GPO as 'Enforced' does nothing. Surely this setting should be overridden by the policy I have set?

Thanks in advance for any help.

Adrian
0
Comment
Question by:arbrctb
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
6 Comments
 
LVL 4

Expert Comment

by:bominthu
ID: 40437279
If you would like to know which policy applied to client machine in domain environment, you should run rsop.msc in RUN

Not gpedit.msc

Gpedit.msc is for Local machine group policy.
0
 

Accepted Solution

by:
arbrctb earned 0 total points
ID: 40437296
Hi,

I've just gone back to this and the policy has now applied.

I'd already ran a gpupdate /force and restarted twice - is there any reason why this policy has only taken effect now?

Thanks,
Adrian
0
 
LVL 4

Expert Comment

by:bominthu
ID: 40438033
If you have ran Gpupdate it should be updated in next restart.

If it is not, you need to check in your server event viewer if there is anything related to GPO
0
 

Author Comment

by:arbrctb
ID: 40444712
Thanks for your help.
0
 
LVL 35

Expert Comment

by:Seth Simmons
ID: 40855323
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question