Windows networking Domain Groups on local Computer

steelio

Senior member
Jul 8, 2004
375
0
0
Ok I am having a little bit of difficulty with my whole group policy etc. I have everything good, but the domain groups are not really showing up on the local computer. I can add them to each computer but there should be a way to import them or a setting maybe even in GP.

Basically I am setting security for a directory but the group is not on the local computer.

Also if there are some good sites with some good info that would be handy.
Thanks!
 

GeekDrew

Diamond Member
Jun 7, 2000
9,099
19
81
File system security doesn't really have anything to do with group policy (at least in this context, assuming I'm reading the rest of your post as you intended).

Is the directory for which you are wanting to set security housed on each of the local workstations, or is it on a single workstation or server? Where are you looking (what screen(s) are you using) when you conclude that domain user groups are not showing up on the local computer? Also, is the local computer a member of the domain holding the user groups you are looking for? What did you do to create the groups in the domain/directory?

Need more info. ;)
 

steelio

Senior member
Jul 8, 2004
375
0
0
well lets just start on the workstation level. It only shows the local users and groups in the computer management. Lets just start on getting it on the domain 100%. I will worry about groups etc. later.
If I add the domain group to the local computer everything works like I want it too, but it is getting that group on the workstation that is giving me fits or getting the rights all the way to the workstation level.

Basically here is what is going on.
I have a domain with users and groups.
I have a workstation that is on that domain and can log in no problems.
I have a GP setup on the domain that gives the users rights on the workstations.
I log in on the workstation I do not have those rights.
I log in as a domain admin I do and can add the domain group that the non-admin users are to the local computer and everything is fine.

Clearer? Sorry I am muscling through this.
 

Allanv

Senior member
May 29, 2001
905
0
0
So is the Directory you want security enabled on, a network share or a local directory?
 

GeekDrew

Diamond Member
Jun 7, 2000
9,099
19
81
Originally posted by: steelio
I have a GP setup on the domain that gives the users rights on the workstations.
I log in on the workstation I do not have those rights.
I log in as a domain admin I do and can add the domain group that the non-admin users are to the local computer and everything is fine.

What rights, specifically, are you talking about within Group Policy?

When you log in as a domain admin, how is it (what screens/steps are you following) that you are adding the domain group to the local computer?

Perhaps I don't fully understand what you are trying to accomplish (exactly).
 

steelio

Senior member
Jul 8, 2004
375
0
0
2003..Active Directory, but on the local machines. Just the %systemdrive% on the local machine.
The domain Admins have the rights other groups do not.
"Perhaps I don't fully understand what you are trying to accomplish (exactly). "
I think it is me that does not understand :)

Basically what I am trying to do is open up the C: drive so a file can be downloaded and put on the local drive via Citrix from a business system we "upgraded" to. And instead of changing the location for these hundreds of users I want to just allow them to write and modify on the C: (%systemdrive%)

Where should I make this change maybe is a better question I should ask?

Thanks!
 
Mar 26, 2008
148
0
0
Is the DNS service on the DC configured correctly? It seems like that may be a possible issue since the clients aren't "seeing" the groups/OUs.

Have you considered putting the file(s) on a network share and having the users just access the files that way?
 

steelio

Senior member
Jul 8, 2004
375
0
0
Ok yup I think that was my problem. In the domain controller there was a group "everyone" but in AD users and groups there was not an "everyone" group. ;)