Univention Bugzilla – Bug 37188
GPO security filter for domain computers doesn't work
Last modified: 2015-04-21 16:10:28 CEST
+++ This bug was initially created as a clone of Bug #37101 +++ Ticket #2014090221000218 With UCS 4.0 and S4 you cannot use the group "Domain Computers" as a security filter - gpresult doesn't "see" the clients as members of the security group and so the gpo is not executed. In AD Users- and Groups Tool the membership is correct, samba-tool shows it also. With a native 2012R2 AD, the same thing works like expected. I only saw one difference: UCS 4.0 with Samba 4 uses the english names, the AD used "Domänencomputer". But as this is the same for every other relevent naming I don't think that this could be the part in question... The group itself is shown correctly in S4, also the well know sid (515) is correct.
First, we will only fix it for UCS 4. If it is a problem, please reopen.
OK