TwistedHelixis Posted February 27, 2023 Posted February 27, 2023 Hi all. I am cleaning up some of our security groups and wanted to remove a couple from all the clients laptops local admin groups I have removed the groups that were listed in the restricted groups gpo (computer policy), but if I run gpupdate /force on a client pc the groups do not get deleted from the local admin group. I can't see any other policies being applied. Any pointers?
psydii Posted February 27, 2023 Posted February 27, 2023 It's been years since I last used that (GPP is probably better for this). So basic questions first: Did you wait for policies to replicate to all DCs? Have you tried rebooting the workstation? Now onto the guess work, becasue I remember something odd here but it was so long ago. I took a quick loot at https://learn.microsoft.com/en-us/troubleshoot/windows-server/group-policy/description-of-group-policy-restricted-groups and I am wondering: if the setting is empty (i.e. not putting any groups into the local group), perhaps the policy doesn't apply i.e. doesn't remove the group that previously had been put in there? I seem to recall I ended up using GPP to remove specific users / groups from a time when another admin had (long ago) tattoo'd some memberships. It did unfortunately result in error in the event logs when it continued to try to remove the users/groups after its initial success, but at least they were gone.
jthompson Posted February 27, 2023 Posted February 27, 2023 That would be my guess, too. If the option in the GPO is now set to 'Not configured', enable it again but with something suitably benign.
TwistedHelixis Posted February 27, 2023 Author Posted February 27, 2023 (edited) OK so things have got a bit worrying. I was just about to hand out a new PC (setup today) and just double checked the local admin groups. This pc did have all the groups deleted, but was also missing a few more groups. Playing around on the DC it doesnt seem to make a difference if ai add or remove groups to restricted groups, its just not applying to the PC. So next I creates a GPP local users & groups settings, created a new OU, dumped both the GPO and computer in that OU and it now has the correct groups listed in the local admin group. This is a single DC On the laptop I am running gpupdate /force Q1 - If the option in the GPO is now set to 'Not configured', enable it again = I cant see anywhere that says its not configured. Q2 - Should I just move over to GPP users and groups? EDIT, now changed to GPP users and groups are not getting updated on the laptop. Going to take a break and look at this in the morning. Edited February 27, 2023 by TwistedHelixis
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now