A
A
antonkovich2014-10-15 21:07:40
Active Directory
antonkovich, 2014-10-15 21:07:40

How quickly does a user group change in Active Directory reach the workstation?

Actually, I include the user in the group having access to a network resource. The opportunity to use this resource will not come immediately. What does this time lag depend on? How is it controlled (forced)?

Answer the question

In order to leave comments, you need to log in

2 answer(s)
P
powersa, 2014-10-16
@antonkovich

the user's ability to use the resource will appear immediately after the re-login (when the security identifiers are rebuilt).
Another question is how quickly the changes will be replicated to other controllers.
within the same site - almost instantly, outside - depends on the replication settings.
sort of like that.

L
L_V_S, 2014-10-15
@L_V_S

The default update interval on a domain controller is 5 minutes, on all other computers it is 90 minutes with a half-hour variation so as not to overload the domain controller with massive simultaneous client requests. That is, in fact, the effective update window on a regular computer (not a domain controller) is from 90 to 120 minutes.
You can force force
technet.microsoft.com/en-us/library/cc739112(v=ws....

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question