local policy not applied on local admin

I have a workstation within a domain. whenever I update the domain policy, it get reflected on all machines. but when I update the local policy for a local admin "called root", it wont reflect on that user. I have the "turn off local group policy objects processing" set to not configured. what I want to do is for the local admin "root" to have privilege on a specific MMC snap-in. so I added the group policy object editor on MMC, and from local users or groups selected the "root" user "in fact I configured all the local groups and users", and then opened the microsoft management console under windows components, then I enabled "restrict users to the explicitly permitted list of snap-ins" and enabled only one snap-in from restricted/permitted snap-ins list. afterwards when I open the MMC in the root user context I expect to only show that one snap-in I enabled. but it sadly shows all the snap-ins.

how to correct this

March 24th, 2015 8:27am

Hi Haster,

Would you please check if the local policy applied or not and if there's any other group policy might take higher priority over the local policy you've configured?

You can logged in the workstation with the local admin account and open the Command Prompt, in the Command Prompt type:

Gpresult /h xx.html

It will generate a detailed RSop report, the .html file could be founded under the %system root%\Users\"your log in account"\xx. html.

With this report you could have a overview of all the group policies which applied on the machine and the current log on user, and which group policy is the winner.

Hope it helps.

Feel free to post back, if any concerns.

Best Regards,

Elaine

Free Windows Admin Tool Kit Click here and download it now
March 25th, 2015 7:31am

hi Elaine,

I ran the gpresult, and under user configuration it tells "Applied GPOs: none, Denied GPOs: none".

March 25th, 2015 9:27am

as I mentioned before I've edited the policy for all local accounts "root, administrators and non-admins", but when I run gpresult under root user context it gives the following "Applied GPOs: none, Denied GPOs: none".

any updates regarding how to resolve this issue?

Free Windows Admin Tool Kit Click here and download it now
March 29th, 2015 2:01am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics