| Dan Kyle 2006-11-13, 8:59 am |
| OK..so I created a new W2K3 server...installed IIS with the defaults. The
IUSR and IWAM users were added to the required groups. I opened the Local
Security policy and deleted them from the groups...and rebooted. Lo and
behold...they were BACK. It looks like this is not an SCW issue.
Now...again..what is causing this. Looks like you may have not been vocal
enough to have them not add user rights for the IIS users.
Let me know what you find.
Thanks
Dan
"Dan Kyle" <beaker@Spamsucks.com> wrote in message
news:%23hRszACBHHA.3540@TK2MSFTNGP03.phx.gbl...
> Thanks again for the information. I can also perform the test you suggest
> and post the results.
>
> I do have more to add. I left the Server for a bit and returned to it and
> checked the Local Security policy...and found the IUSR and IWAM users to
> NOT be there.
>
> SO..I rebooted and looked at the Local Security Policy and foun them to be
> there (even though the winlogon.log showed them as being removed). I then
> ran a GPUPDATE /FORCE ..looked at the Local Security Policy and they were
> GONE! CHecked the winlogon.log and again it showed them as being
> removed...only this time they WERE removed. It looks like this is only an
> issue at boot time and once the GPO's apply for a second time..the GPO
> hierarchy takes precedence.
>
> So..why do the SCW settings take precedence at boot and then have to wait
> for the first GPO refresh to occur before being taken out?
>
> Dan
>
>
>
> "Roger Abell [MVP]" <mvpNoSpam@asu.edu> wrote in message
> news:%23ycMjTBBHHA.992@TK2MSFTNGP03.phx.gbl...
>
>
|