boomam Posted February 28, 2008 Posted February 28, 2008 Hi. A while back when we got some new machines, i had to create a custom GPO on them so the drives and start menus appeared for them, as they had different setups than the rest of the machines on the network. A niggling problem ive had since then is that even when i log into them as administrator, everythings as if im a normal user, including access rights. Any idea why that happens? Thanks in advance all. .
maf_001 Posted February 28, 2008 Posted February 28, 2008 This sounds like the workststion has copied the standard user account over the default user account, if this happens all the standard users gpo will apply to everyone who logs in. hope this helps
boomam Posted February 28, 2008 Author Posted February 28, 2008 How do i fix it then? Copy the profile from a working profile, but change the start menu shortcuts to what i wanted them to be?
pallen Posted February 28, 2008 Posted February 28, 2008 Have you got loopback enabled on the OU the computers are in so that settings apply to the computers regardless of user that logs on?
elsiegee40 Posted February 28, 2008 Posted February 28, 2008 Can you copy the Administrator from a similar machine that works and replace the one on the problem machine?
boomam Posted February 29, 2008 Author Posted February 29, 2008 Have you got loopback enabled on the OU the computers are in so that settings apply to the computers regardless of user that logs on? Yes, as at the time, using Loopbacks was the only way i could get drives and start menus to be the custom ones i wanted. I was thinking it might be that, but have been putting off fixing it because i didnt want to faff with potentially broken shortcuts on the workstations.
pallen Posted February 29, 2008 Posted February 29, 2008 Could you not create a policy for the admin users and put it into the same OU forcing it to overide the restrictions you set? Never really used loopback too much, but I was thinking of doing the same thing as you have to apply start menu settings for each room. There is probably an easier way to do it though and i'm sure someone will suggest it.
ChrisH Posted February 29, 2008 Posted February 29, 2008 I have had a loopback policy sting me before. I couldnt add/remove hardware as admin. Do a report in the GPMC and see what settings you are receiving and from where.
jsnetman Posted February 29, 2008 Posted February 29, 2008 had the same problem a while ago when I messed around with the default profile. As a quick workaround I included a logon script for the admin account that deleted the contents of the registry key HKEY_CURRENT_USER\Software\Policies. This removes the restriction but you must log off and back on. A bit of a pain but its better than rebuilding the whole school.
boomam Posted March 5, 2008 Author Posted March 5, 2008 So your script removes those keys at each logon for administrator? Does that affect any pupils who log on afterwards?
jsnetman Posted March 5, 2008 Posted March 5, 2008 No because when they logon I believe the registry is rewritten with their group policy. I haven't had any problems with security using the method described in the previous post.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now