URL: https://github.com/SSSD/sssd/pull/5241 Title: #5241: GPO: respect ad_gpo_implicit_deny when evaluation rules
sumit-bose commented: """
I can't reproduce this. I have two users 1) Administrator, 2) vagrant. I allow access to the Administrator. Administrator is allowed to login as expected, vagrant is not able to login either way regardless on the option settings because an applicable gpo is found and the user is not explicitly allowed.
Hi,
the issue happens when there is no allow rule, i.e. RemoteInteractiveLogonRight is empty.
bye, Sumit
"""
See the full comment at https://github.com/SSSD/sssd/pull/5241#issuecomment-678307489
sssd-devel@lists.fedorahosted.org