I have an OU called Test Desktops. I have test workstations in this OU. I created and linked a GPO to this OU called Restrict test allowed logons. Created a group with users allowed to logon to the test workstations. Added this group to the allow logon locally in the computer configuration settings along with administrators and domain admins. disabled "do not require ctrl+Alt+del" setting. security filtering has authenticated users and domain users (tried with and without domain users).
We tested with a domain user not in the allowed group. The test user is able to login. I have run GPupdate /f. shut down the workstation. I run gpresults. it states that the GPO is applied. If I look at the local security settings on the workstation, allow logon locally is not changed. Any help will be appreciated. Thank you.