When using Group Policy to set users.allow (or <pamservice>.allow) sometimes users are fully qualifed and other times not.
For example
YOURDOMAIN\username
vs
username
There was a behaviour change between 3.3.2, and version 3.5 of the Windows admin tools. Version 3.5 and above will always qualify the groups names after you have added them, 3.3.2 and below will not. If you are using a mixture of 3.5+ and pre-3.5 admin tools, you may see the users.allow change dependent on which admin tools version is used to do the update.
Edit the Group Policy on 3.5, removing and re-adding the users/groups. Avoid editing the policy on pre 3.5 machines.
© 2024 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy Cookie Preference Center