synaesthesia Posted May 10, 2018 Posted May 10, 2018 This seems to be a very common error googling around, however the fixes are either hodge-podge or singular and don't/won't apply to multiple machines. So, windows 10 machine (both 1709 Pro which I'm setting up for a student currently, or LTSB 1607) absolutely fine until it joins the domain, at which point the start menu and modern apps cease to work. Out of all the fixes around such as the rubbish Start Menu Diagnostic tool etc do absolutely nothing, however one fix that does work is registry permissions. For some reason, the moment the machine joins the domain it overwrites permissions for HKEY_CLASSES_ROOT and removes read rights for "ALL APPLICATION PACKAGES". Now, go into regedit as an admin user, readd those rights replacing permissions with inheritables and everything instantly works again as it should. Fantastic, now common sense dictates all I'd need to do is throw that in a GPO. So, done exactly that, gpresults tells me it applies succesfully although it actually hasn't, those rights are yet again gone and the start menu ceases to work again after restart. There's nothing in group policy which is dictating this behaviour, at least not that I can find. I've made testing OU's up with no propogation of GPOs to ensure it's not an errant GPO somewhere, with zero luck. Has anyone else come up against this, and if so how did you overcome it?
Arthur Posted May 10, 2018 Posted May 10, 2018 absolutely fine until it joins the domain, at which point the start menu and modern apps cease to work. AppLocker/SRP policy blocking modern apps? Do you use Impero?
synaesthesia Posted May 10, 2018 Author Posted May 10, 2018 No, not those as we've not had any w8/8.1/10 devices otherwise on the network. But yes, we use Impero but haven't installed the client on this machine (yet)
synaesthesia Posted May 10, 2018 Author Posted May 10, 2018 Think I may have found it, a domainwide policy setting permissions on HKLM/Classes which then seems to roll down to Root. That's fixed it
SavvyGolfer Posted May 16, 2018 Posted May 16, 2018 Think I may have found it, a domainwide policy setting permissions on HKLM/Classes which then seems to roll down to Root. That's fixed it synaesthesia, any chance you can list out exactly what you did with the domain wide policy to fix this issue? This issue has been diving me nuts for some time now. Thanks
rh91uk Posted May 16, 2018 Posted May 16, 2018 I have seen this error myself and it can be because you have a default profile in your netlogon. Only happens with 1709 and have to downgrade (or upgrade to 1803) which fixes it.
Arthur Posted May 16, 2018 Posted May 16, 2018 any chance you can list out exactly what you did with the domain wide policy to fix this issue? It sounds like a setting that was specific to @synaesthesia's network? There isn't anything out-of-the-box that sets permissions on HKLM/Classes.
synaesthesia Posted May 17, 2018 Author Posted May 17, 2018 Indeed @Arthur - very likely to have been a bodge (fix) for something historic.
PotNoodleTech Posted September 19, 2018 Posted September 19, 2018 Aha! I am getting this exact problem on EDU 1803! Soon as I join the domain the start menu and task bar stops working for all users even local admins. Will look in GPOs for any HKLM/Classes entries now as it must be something similar. Thanks!!!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now