Re: security updates

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Jason Tan (v-jasont_at_online.microsoft.com)
Date: 03/01/05


Date: Tue, 01 Mar 2005 13:09:28 GMT

Hi Reed,

Thanks for reply soon!

Based on the problem description, we need to check group policy to ensure
users have sufficient right.

Step 1: Check User Rights Assignment
======================================

1. Logging on system as administrator account.

2. Click Start and click Run, type gpedit.msc in the open box and hit OK.

3. In the left pane, expand [Computer Configuration]\[Windows
Settings]\[Security Settings]\[Local Policies] and highlight [User Rights
Assignment].

4. In the right pane, double click the item [Backup files and directories].

5. Click Add, drop down the box in top after "Look in" and select your
computer name, and add the following users. (where Computer_name refers to
your actual computer name, your_username refers to your actual log in name)

Computer_name\Administrator (local administrator)
Computer_name\your_username (your log in name, such as ACTTODAY\mhelton)
Administrators (administrators group, if you find more than one
administrators in the list, please add them all)
Everyone
System

6. Repeat the similar steps for the following user rights
- Restore files and directory
- Manage auditing and security logs
- Backup files and directories
- Take ownership of files and folders.

7. Make sure the "Effective Policy Settings" is checked actually instead of
grayed out with no checks.

8. Exist policy editor and ensue you log on computer_name (this computer)
as Administrator. Try to install the update again.

If you found although you have checked the box for "Local Policy Settings",
the "Effective Policy Settings" is still grayed out with no checks, this
indicates the current Effective Policy settings could have been inherited
from policies within the domain. If this is the case, those domain policies
have to be changed. For your comparison, I am sending you my "Effective
Policy Settings" screenshot. You can see the "Effective Policy Settings"
boxes are checked.

Step 2: Please create a new account with administrator permissions and test
the issue with the new account.

Step 3: If the issue persists, please help me to collect MPS_Setup report.
========================================================
Here are the steps:

Download the MPSRPT_SETUPPerf.EXE from the following link and then run this
tool to gather some information from the problematic computer:

http://download.microsoft.com/download/b/b/1/bb139fcb-4aac-4fe5-a579-30b0bd9
15706/MPSRPT_SETUPPerf.EXE

To run this tool:

1. Double-click on the MPSRPT_SETUPPerf.EXE file.

I understand this process may take some time, however it will not have a
negative effect on the performance.

2. A CAB file will be generated in the
%systemroot%\MPSReports\Setup\Reports\Cab directory called
%COMPUTERNAME%_MPSReports.CAB. The CAB file will contain the reports
generated by the MPS Reporting Tool.

3. Send the CAB file to me as an attachment.

Note: please send the attachment to v-jasont@microsoft.com
 
If there is anything that is unclear, please feel free to let me know.
Thanks for your time!

Thanks & Regards,

Jason Tan

Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security

=====================================================

When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.

=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.



Relevant Pages

  • Re: Must all users be administrators?
    ... The familiar look of the AD objects tree you see in Group Policy Editor is ... This seems modestly confusing to an SBS Administrator because there's very ... those rights happen to be nearly unlimited. ... sit a workstation logged on as the Local Administrator, by default, there ...
    (microsoft.public.windows.server.sbs)
  • Re: The local policy of this system does not permit you to logon i
    ... Security policies were propagated with warning. ... Error 0x534 occurs when a user account in one or more Group Policy objects ... I have checked the security policies & the administrator profile is not ...
    (microsoft.public.windows.server.sbs)
  • Re: Administrator unable to log on Interactively
    ... Firstly i tried accessing the domain controller C drive ... I think the policy has been changed in the "local security ... >> administrator is not able to log on interactively. ... >Interactive Logon setting takes precedence over the Allow ...
    (microsoft.public.win2000.security)
  • Re: Administrator is not the "Boss" on this machine.
    ... policy, I'd see two columns, one for "setting" ... > you can not run that command you may not be logged on as an administrator. ... > If you messed with Group Policy settings for user configuration the solution above ...
    (microsoft.public.win2000.security)
  • Event 1202 Warnings after Renaming Administrator Acct on SBS2003
    ... one referencing the original administrator account: ... specific policy setting that was flagged with a big, ... I used an incorrect procedure to rename the ...
    (microsoft.public.windows.server.general)