Forum Discussion
Forcing effect after assigning AD user to local admin group
Hello,
I have the following conundrum that I hope somebody could answer me. It's about security and Active Directory.
Let's say I have an AD called mydomain.com
I have an simple AD user called mydomain\user1
I have an AD member computer called CompA.
I need to grant local admin rights of CompA to mydomain\user1.
So, I create an AD group called mydomain\GADMA.
In CompA, the local Administrators group contains mydomain\GADMA as member.
And the AD group mydomain\GADMA contains mydomain\user1.
mydomain\user1 logs on CompA but he does NOT have local admin right immediately (even though the config is correct as you can see). Sometimes he has to wait a few hours, but sometimes he has to wait 24 hours to take effect!
My question:
Is there any command to shorten the waiting time? Or he really has to wait 24 hrs or even more?
1 Reply
- tfseakCopper ContributorNo reply? Seriously? That means even Microsoft has no definite answer, right?
Shame on you, Microsoft.