Click here to get back home

2003 Policy doesn't take effect until reboot

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
2003 Policy doesn't take effect until reboot Rob S 06-06-2006
Posted by Rob S on June 6, 2006, 3:54 am
Please log in for more thread options
Is it a bug, or as designed that when I change the policy:

Default Domain Controllers/Computer/Windows Settings/Security Settings/Local
Policy/Allow Log On Locally

to add a group of users, that this doesn't take effect until I reboot the
server. If I just log off and log on as a user in the group I added I still
can't get access. Once rebooted I can login as this user.

The environment has just one 2003 R2 SP1 server acting as domain controller,
Active Directory, DNS, WINS etc.

rgds

-Rob
robatwork at mail dot com

Posted by Laura E. Hunter [MVP] on June 6, 2006, 7:34 am
Please log in for more thread options
What you're seeing at work is actually the Group Policy Refresh cycle:
changes you make to GP don't take effect immediately since settings are
cached on the machine for a certain length of time: 90 minutes by default
for member servers and workstations, 2 minutes by default for domain
controllers. You can force Group Policy to refresh by rebooting the
computer or simply typing 'gpupdate /force' from the command prompt.

See the following KB for more details:

http://www.vet.upenn.edu/newsandevents/news/Barbaro.htm

HTH
--
Laura E. Hunter
Microsoft MVP: Windows Server - Networking
Responses provided as-is; no warranties expressed or implied

> Is it a bug, or as designed that when I change the policy:
>
> Default Domain Controllers/Computer/Windows Settings/Security
> Settings/Local
> Policy/Allow Log On Locally
>
> to add a group of users, that this doesn't take effect until I reboot the
> server. If I just log off and log on as a user in the group I added I
> still
> can't get access. Once rebooted I can login as this user.
>
> The environment has just one 2003 R2 SP1 server acting as domain
> controller,
> Active Directory, DNS, WINS etc.
>
> rgds
>
> -Rob
> robatwork at mail dot com



Posted by Roger Abell [MVP] on June 7, 2006, 1:42 am
Please log in for more thread options
Laura has provided correct analysis of what you likely are seeing.
But as you state you have changed the Default Domain Controller
GPO, and its refresh cycle is quite short, it may be worth adding
that the application of a change to the DDC GPO has a latency
that can also include replication time if the GPO change was made
while focused on a different DC from the one where one is testing
to see if the change is yet effective.

> Is it a bug, or as designed that when I change the policy:
>
> Default Domain Controllers/Computer/Windows Settings/Security
> Settings/Local
> Policy/Allow Log On Locally
>
> to add a group of users, that this doesn't take effect until I reboot the
> server. If I just log off and log on as a user in the group I added I
> still
> can't get access. Once rebooted I can login as this user.
>
> The environment has just one 2003 R2 SP1 server acting as domain
> controller,
> Active Directory, DNS, WINS etc.
>
> rgds
>
> -Rob
> robatwork at mail dot com



Similar ThreadsPosted
reboot December 26, 2005, 6:30 am
Effect of NetBIOS Over TCP on File Sharing September 27, 2005, 9:55 pm
Turn off prompt after reboot August 23, 2006, 9:31 am
permissions change after a reboot... September 19, 2006, 1:33 am
Strange effect with inheritence flags on Windows XP and NT 4 June 13, 2007, 11:19 am
What security policies effect tasklist.exe password prompt behavior? February 29, 2008, 9:29 am
Windows 2003 domain password policy September 26, 2006, 9:53 pm
Windows 2003 audit Policy amended October 29, 2006, 7:32 pm
local security policy on windows 2003 server April 16, 2007, 10:28 am
Password Security Policy for Local on Window 2003 March 14, 2008, 4:10 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap