Odd group behavior


we have windows 2008 ad domain running @ windows 2008 functional level.  1 domain controller running windows server 2008 r2 enterprise , other running windows server 2008 (32-bit).  last several months, i've noticed members of group can not been idetified.  example, group "developers" added local system group of "event log readers" on windows server 2008 r2 system.  members of "developers" group not access event logs.  however, when removed group , added individual members directly, had access.  when switch "developers" , removed individual members, access denied once again event logs.  have had same issue few security devices , work around has been added individual members instead of ad group.

i'm open ideas on how resolve or narrow down causing strange issue.  thank you!

paul



Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file