question

SeemaKanwalGurmani-8582 avatar image
0 Votes"
SeemaKanwalGurmani-8582 asked FanFan-MSFT commented

We have AD users Authentication Issue

56576-1.jpg

Dear Community,

We have created three groups in AD Domain Controller for authentication of our AD Users (i.e. Internet Officers (with restriceted ), Middle Management(partially restricted), Top Management(no restriction)).
These groups are called in Firewall as the restriction level of internet is different and we control users internet access on these groups basis.

The problem occurs when I try to change a user's group. I go to dc , I remove it from let's say internet officer group and make it member of Top managment ,the group doesnot get updated on client's system , I ran whoami /group command on user system as a troubleshooting and ran"gpupdate /force" command, rebooted user system but it still shows the old Internet officer group by running "whoaam /group" command. When checked at firewall's end it was still authenticating from same old group however on domain controllers (ALL) it was showing updated group under user & groups user properties.

I want to ask as to why dc is not updating from previous group?

Kindly guide me .


56781-2.jpg


windows-active-directorywindows-server-2012
1.jpg (94.0 KiB)
2.jpg (388.5 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

OsamaMansoor-7723 avatar image
0 Votes"
OsamaMansoor-7723 answered

i am facing same issue.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

HG-0019 avatar image
0 Votes"
HG-0019 answered

Hi,

delete the Kerberos Ticket.
klist purge

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

FanFan-MSFT avatar image
0 Votes"
FanFan-MSFT answered

Hi,
Run the command :klist purge to clear the cached credentials to check if it works.
If not , sign out the user and sign in again.
If there are any updates , welcome to share here!
Best Regards,

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

OsamaMansoor-3160 avatar image
0 Votes"
OsamaMansoor-3160 answered

Sorry,56967-4.jpg not worked for me.
Also rebooted multiple times but it looks like groups is stucked



4.jpg (507.9 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

deepakkodiyil avatar image
0 Votes"
deepakkodiyil answered

Are you facing the issue even after restarting the machine ? If so there could be a chance of AD replication issue.

1) Please run below command to see the DC its maintaining secure channel with.

 nltest /dsgetdc:"type your domain name"

2) Connect Active directory Users and computers and change domain controller to the DC obtained on step 1
3) Check user membership on that domain controller. If membership is present , there is a problem with AD replication.

Regards,
Deepak M

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

OsamaMansoor-3160 avatar image
0 Votes"
OsamaMansoor-3160 answered OsamaMansoor-3160 edited

I ran the command on my laptop and attached is the result.
57512-capture.jpg



capture.jpg (101.6 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

OsamaMansoor-3160 avatar image
0 Votes"
OsamaMansoor-3160 answered

From another computer with my login I can see that the updated group is updated please see below.

57406-another-system.jpg



another-system.jpg (265.0 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

OsamaMansoor-3160 avatar image
0 Votes"
OsamaMansoor-3160 answered

From My, System Group is not updated.

57446-my-system.jpg



my-system.jpg (475.7 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

deepakkodiyil avatar image
0 Votes"
deepakkodiyil answered OsamaMansoor-3160 commented

Have you checked the membership on domain controller ? Also please conform if you have restarted the affected system.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Yes after restart group membership updated but i be surprised why i take too much long time to update.

0 Votes 0 ·
OsamaMansoor-3160 avatar image
0 Votes"
OsamaMansoor-3160 answered

Is this looking Domain Replication issue?

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.