Jump to content

Recommended Posts

Posted

Hi all. I am cleaning up some of our security groups and wanted to remove a couple from all the clients laptops local admin groups

 

I have removed the groups that were listed in the restricted groups gpo (computer policy), but if I run gpupdate /force on a client pc the groups do not get deleted from the local admin group.

 

I can't see any other policies being applied.

Any pointers?

Posted

It's been years since I last used that (GPP is probably better for this). So basic questions first: Did you wait for policies to replicate to all DCs? Have you tried rebooting the workstation?

 

Now onto the guess work, becasue I remember something odd here but it was so long ago. I took a quick loot at https://learn.microsoft.com/en-us/troubleshoot/windows-server/group-policy/description-of-group-policy-restricted-groups and I am wondering: if the setting is empty (i.e. not putting any groups into the local group), perhaps the policy doesn't apply i.e. doesn't remove the group that previously had been put in there?

 

I seem to recall I ended up using GPP to remove specific users / groups from a time when another admin had (long ago) tattoo'd some memberships. It did unfortunately result in error in the event logs when it continued to try to remove the users/groups after its initial success, but at least they were gone.

Posted (edited)

OK so things have got a bit worrying.

 

I was just about to hand out a new PC (setup today) and just double checked the local admin groups. This pc did have all the groups deleted, but was also missing a few more groups. Playing around on the DC it doesnt seem to make a difference if ai add or remove groups to restricted groups, its just not applying to the PC.

 

So next I creates a GPP local users & groups settings, created a new OU, dumped both the GPO and computer in that OU and it now has the correct groups listed in the local admin group.

 

This is a single DC

On the laptop I am running gpupdate /force

 

Q1 - If the option in the GPO is now set to 'Not configured', enable it again = I cant see anywhere that says its not configured.

Q2 - Should I just move over to GPP users and groups?

 

EDIT, now changed to GPP users and groups are not getting updated on the laptop. Going to take a break and look at this in the morning.

Edited by TwistedHelixis

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...