On Fri, Feb 24, 2017 at 10:06 AM, Michael Wandel <m.wandel@t-online.de> wrote:
On 24.02.2017 15:56, Bernard Fay wrote:
> Stopping nscd did not change anything.  "groups username" still shows
> user as member of Administrators.
>

please can you make an ldapsearch for the object username and the output
from getent passwd username.


Thanks Michael,

getent passwd username showed me the mistake.  The user has Administrators as primary group.  In our setup, all users being regular or admin users, should all be in the users group.  Changing this fixed my problem.

Thanks