win2k group membership cache?

From: Anthony Your (
Date: 05/21/02

From: "Anthony Your" <>
Date: Tue, 21 May 2002 11:31:24 -0400


here is the environment:
3 win2k AD controllers (running pure AD)
win2k webservers, etc.

I have NTFS permissions set using domain groups on folders used by IIS on
member web servers. If I change group membership and force sync the AD
controllers, it still takes several hours for the permissions to propagate.
I don't know if IIS caches group membership or if it is the NTFS file
system. Can I force a flush of this cache? Or do I have some other problem
such as a GPO or some setting in the domain? Restarting the server or the
webservice every change is not an option...sorry.