Hi guys,
Currently we assign admin rights through AD user groups to machine. This works fine when on our organisations network. However, if we take a machine off the network users lose admin rights.
They log in off the network and they are seen as not a member of the AD groups so privileges are revoked.
Is there a way you can get these to stick? It seems a bit volatile that not being able to talk to our directory server is an assumption that the user is not a member of the group.
I have a few ideas on how I can force it but its a bit messy.
