Restricted Groups not taking effect right away
Hi all,
I posted this in another group but I don't think it was the right group, so
I'll post here again.
I have a small yet vital application that is distrobuted through an internal
website. The client goes to the website, downloads the cab file and installs
an Active-X control automatically.
We're trying to remove local administrator rights from machines, but to
perform the upgrade for this application's ActiveX, the user will have to be
administrator for a brief period.
I created a GPO that adds the "NL7Pilot" group as a member of the Local
Administrators group through Restricted Groups, as well as the Domain Admins
group, the local administrator user, and the tech support group.
If I "gpupdate /force", reboot the computer, and then log in as a user that
is a member of "NL7Pilot", the user does not have administrator rights.
However, if I go to the command prompt and execute 'net localgroup
administrators' the "NL7Pilot" group shows up as a member of administrators.
If I log out, and then immediately log back in as the same user, the user
will then have administrative rights. It's almost acting as if the restricted
groups settings aren't taking effect until a user logs in the first time. I
thought since it was a computer policy, it should take effect as soon as the
computer starts up, or as soon as a policy update occurs (either in the
background or as a result of a 'gpupdate /force')
Am I not understanding the behaviour of restricted groups properly, or is
there something else I'm not doing.
Thanks,
Don
|