Jump to content

Recommended Posts

Posted

This seems to be a very common error googling around, however the fixes are either hodge-podge or singular and don't/won't apply to multiple machines.

 

So, windows 10 machine (both 1709 Pro which I'm setting up for a student currently, or LTSB 1607) absolutely fine until it joins the domain, at which point the start menu and modern apps cease to work.

Out of all the fixes around such as the rubbish Start Menu Diagnostic tool etc do absolutely nothing, however one fix that does work is registry permissions. For some reason, the moment the machine joins the domain it overwrites permissions for HKEY_CLASSES_ROOT and removes read rights for "ALL APPLICATION PACKAGES".

Now, go into regedit as an admin user, readd those rights replacing permissions with inheritables and everything instantly works again as it should. Fantastic, now common sense dictates all I'd need to do is throw that in a GPO. So, done exactly that, gpresults tells me it applies succesfully although it actually hasn't, those rights are yet again gone and the start menu ceases to work again after restart.

 

There's nothing in group policy which is dictating this behaviour, at least not that I can find. I've made testing OU's up with no propogation of GPOs to ensure it's not an errant GPO somewhere, with zero luck.

 

Has anyone else come up against this, and if so how did you overcome it?

Posted
absolutely fine until it joins the domain, at which point the start menu and modern apps cease to work.

AppLocker/SRP policy blocking modern apps?

 

Do you use Impero?

Posted
Think I may have found it, a domainwide policy setting permissions on HKLM/Classes which then seems to roll down to Root. That's fixed it :D

 

synaesthesia, any chance you can list out exactly what you did with the domain wide policy to fix this issue?

 

This issue has been diving me nuts for some time now.

 

Thanks

Posted
I have seen this error myself and it can be because you have a default profile in your netlogon. Only happens with 1709 and have to downgrade (or upgrade to 1803) which fixes it.
Posted
any chance you can list out exactly what you did with the domain wide policy to fix this issue?

It sounds like a setting that was specific to @synaesthesia's network? :confused:

 

There isn't anything out-of-the-box that sets permissions on HKLM/Classes.

  • 4 months later...
Posted

Aha! I am getting this exact problem on EDU 1803! Soon as I join the domain the start menu and task bar stops working for all users even local admins.

 

Will look in GPOs for any HKLM/Classes entries now as it must be something similar.

 

Thanks!!!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...