Specify group names to ignore (lookup)

Specify user groups that are always treated as local when looking up group information, for example, when displaying file ownership.

You can type the list of local group names not stored in Active Directory, separated by a space. This list is then used to disable looking up account information in Active Directory for the groups specified, which results in faster name lookup service for system group accounts such as tty and disk.

You can also enter the file: keyword and a file location. For example:


This group policy modifies the nss.group.ignore setting in the Centrify DirectControl configuration file.

Supported on:

Import system NSSDB to applications

Registry PathSoftware\Policies\Centrify\CentrifyDC\Settings\Login
Value Name{number}
Default Value


Administrative Templates (Computers)

Administrative Templates (Users)