This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web appliance - Additional policy still applies after user removed from AD group

I am testing the VM appliance. 

The organisation requires that Facebook be blocked for all users, except members of the online communications team. 

The default policy blocks the "Personals and Dating category.

Facebook is classified as "Personals and Dating"

An AD group has been created called "Allow Facebook"

I have added the site to the local site list and tagged it as "Social Networking"

I have created an additional policy to allow members of the AD group to allow sites tagged as "Social Networking" 

Users in the group are able to access Facebook.com

I remove the user from the group, and log them off and back on, they can still access Facebook.com

If I run the Policy Test with the user removed from the group, the site is still allowed.

If I run the Policy Test with a user who has never been in the group, the site is blocked.  

Why could this be? Something to do with groups not syncronising in good time? Can anyone help please?

Thanks.

:34653


This thread was automatically locked due to age.
Parents Reply Children
No Data