Hi
I am using two IAS on two DC's in different sites. Remote access
policies are same on both IAS and are based on user group membership.
When I move user from one group (RAP1) to another group (RAP2) and user
connect to VPN, user still stome time get RAP1 policy instead of RAP2
which group is now member.
But after some time user begin to receive RAP2.
Can someone please explain to me that, why have to pass some time for
change to become effective ?
Is that something with replication or GC, because after change I've
manualy forced repliction between sites and confirmed that user on all
DC's now have membership of new group ?