Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

AD Account group memberships inconsistency

Status
Not open for further replies.

JPJeffery

Technical User
May 26, 2006
600
GB
Hi

I'm trying to get a GPO to only apply to users in a group. Usually, such tasks are almost trivial in nature (I've done it before) but what seems to be happening is that a user's groups memberships are not being picked up correctly by Group Policies.

Sam Vimes is our test user. AD shows he is a member of eight groups and the 'net user vimes_s /domain' command lists the same eight groups.

However, 'gpresult' lists NINE groups (not including the builtin, NT Authority, 'LOCAL' and 'Everyone' groups) but of these nine only six are in the list of eight. in other words, two of the eight are missing according to GPRESULT and there are three extra. Unsurprisingly, the two missing ones are for groups that should filter in GPOs.

I've rebooted the PC a couple of times and even run 'GPUPDATE /FORCE'.

The Event Log is showing some Userenv 1058 and 1030 errors (which are 'Can't access the file gpt.ini' errors, and the GUID mentioned does match the new GPO I've just created), but I don't see how the group memberships are listed as different.

JJ
[small][purple]Variables won't. Constants aren't[/purple]
There is no apostrophe in the plural of PC (or PST, or CPU, or HDD, or FDD, or photo, or breakfast...and so on)[/small]
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top