[THIN] Re: Weird W2K3 GPO issues

  • From: "Andy Friar" <Andy.Friar@xxxxxxxxxxx>
  • To: <thin@xxxxxxxxxxxxx>
  • Date: Tue, 1 Jul 2008 15:06:05 +0100

Check the permissions on the profile.
 
Authenticated Users: Full
 
Rgds
 
Andy

________________________________

From: thin-bounce@xxxxxxxxxxxxx on behalf of Steve Snyder
Sent: Tue 01/07/2008 02:19
To: thin@xxxxxxxxxxxxx
Subject: [THIN] Re: Weird W2K3 GPO issues


Read & Apply

Seems to be related to my mandatory profile, I'll have to pick it apart a bit


On Tue, Jul 1, 2008 at 12:57 PM, Joe Shonk <joe.shonk@xxxxxxxxx> wrote:


        Do the users have read permission but not apply?

         

        Joe

         

        From: thin-bounce@xxxxxxxxxxxxx [mailto:thin-bounce@xxxxxxxxxxxxx] On 
Behalf Of Steve Snyder
        Sent: Monday, June 30, 2008 3:55 PM
        To: thin@xxxxxxxxxxxxx
        Subject: [THIN] Weird W2K3 GPO issues

         

        new build of W2K3R2, all current M$ patches. Server resides in an OU 
blocking GPO inheritance, and I have a GPO applied to this OU with very minimal 
settings for testing using loopback to force user settings. When I logon with a 
dummy user account (my daily account :) ) the policy settings don't apply 
(remove shutdown, disable CMD, etc.) but if I run a rsop.msc it shows the 
settings as being applied. If I make my dummy account a local admin on the box 
then the settings apply. I've enabled debugging and see entries like
        
        USERENV(16fc.15b4) 10:43:09:525 SetRegistryValue: DisableRegistryTools 
=> 1  [OK]
        
        and in the user's registry key 
software\microsoft\windows\currentversion\policies\system the values are set 
properly, they're just not working.
        
        Any thoughts or ideas on whree to look next?


Other related posts: