I am using a domain local group (Call it “Deny”)to phase in the group-policy controlled roll out of Win2k SP3.
Members of the group have Deny permissions to the policy. When I remove them, the policy should be applied, and the service pack should install. This has worked in the past.
However, the install is not occurring. GPRESULT.exe run on the workstation shows that it still believes itself to be a member of the Deny group.
I have verified that the machine accounts have been removed from the Deny group on both DC’s, and have rebooted DC’s and workstations multiple times.
Question: Why does the workstation still think it is in this group…where is it pulling this membership information from? How can I kick it out?