ITGURU Posted June 5, 2017 Posted June 5, 2017 I have a GPO on windows 10 machines (on the latest update) which sets the policy item 'deny logon locally' with a security group of which all staff users are a member of so that only students can login to the computer. However, wanting to open up computers (the same way as I did on windows 7 ones) i add the computer into the policy with the deny setting so it doesnt allow the policy, but still got the message the login type is not allowed. As a full test I removed the GPO object entirely from the student computers group, ran gpupdate /force and checked with gpresult and the entry has gone but still won't allow staff to login. If i run gpedit.msc on the local pc, it is still showing the entry - I can manually remove it and staff can now login, but seems that the policy is not taking any effect on the workstations when remove the GPO or add the deny entry, However, when i add new workstations to the AD group with the GPO applied it adds the entry in, but seems once it has done this it won't remove it or amend it; any ideas?
ADMaster Posted June 5, 2017 Posted June 5, 2017 Most GPOs do not remove the settings once they no longer apply. You can either edit the current GPO to remove staff from the deny logon, or create a new GPO to do it.
ITGURU Posted June 5, 2017 Author Posted June 5, 2017 It did on windows 7 - whenever I added a PC in as an exclusion deny 'read' on the policy and rebooted the computer it picked up the amended policy, remove it from the local policy and users could log in.
ADMaster Posted June 5, 2017 Posted June 5, 2017 These settings are normally in default domain policy so when you remove the policy it is picked up from there instead. Did you block inheritance for your W10 machines to test GPOs? What does gpresult or RSOP have to say?
ADMaster Posted June 6, 2017 Posted June 6, 2017 I just looked at my own policies and it doesn't appear this is in the default policy by default. I'd still look at the inheritance, gpresults, and/or rsop as troubleshooting steps.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now