Re: Is this a GPO setting or not?

From: Bruce Sanderson (bsanders_at_junk.junk)
Date: 08/21/04


Date: Sat, 21 Aug 2004 13:19:32 -0700

Sounds to me that the permissions on the Documents and Setting folder have
been manipulated.

If Users are removed from the permissions on the Documents and Settings
folder, a user that does not already have a profile, can't create one and
you get the message box saying the user profile can not be loaded with a
count down timer.

But, Administrators still have access, so when the user's account is in the
Administrators group, that user can logon and create their profile in
Documents and Settings. The user's account specifically gets Full Control
over its profile folder, so, after the user's account is removed from the
Administrators group, they can still logon and use their profile folder.

-- 
Bruce Sanderson  MVP
It is perfectly useless to know the right answer to the wrong question.
"Charles" <mentaldrowremovethis@gimail.af.mil> wrote in message 
news:277101c4866f$a0efd2e0$a301280a@phx.gbl...
> I'm trying to duplicate a setting on a few of the
> machines I manage that will prevent users from logging
> into the machines unless I go through the Users and
> Passwords Control Panel item or Local Groups and User MMC
> snap-in and give them permission to logon to the
> machine.  They initially have to be input into the
> machine this way with Admin access to the machine and
> then bumped down to a lower permissions level.  If their
> profiles aren't manually added in this manner they get a
> message like this.  "Cannot copy C:\Documents and
> Settings\Default User\Favorites\<insert url here> to
> C:\DOcuments and Settings\<insert User Name
> here>\Favorite\... etc" with a countdown time at the
> bottom.  At the time out they get another message that
> basically tells them to contact the Network Admin because
> their profile could not be created on the machine.  I
> don't have much authority over the User Domain accounts
> so I can't add them to specific OU except at the Local
> machine level but I have complete control over the
> machines themselves.  Is this something that can be done
> via the GPO or Local Security Settings?  Is there another
> MMC snap-in that I can use to duplicate this setting?
> This is the only way I've found so far to prevent users
> from logging into certain machines.  The previous Network
> Admin can't remember what he did to activate this so I'm
> pretty much on my own.  Thanks in advance for any and all
> help.
>
> Charles 


Relevant Pages

  • Re: Unable to delete user profile folder using default Admin. acco
    ... I recognize that this isn't Microsoft Tech Support. ... about removing this pesky little profile folder and I'm done. ... the second account's original profile folder is giving me ... It appeared to have been deleted like the first account when I ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: For those of you who have disabled UAC while using user/admin, you dont have full admin rights &
    ... In Vista, an admin user doesn't have permissions to ... has the ability to take ownership and change permissions. ... all one has to do is add a second user account on the folder ...
    (microsoft.public.windows.vista.general)
  • Re: Unable to delete user profile folder using default Admin. acco
    ... Is anybody else out there who's an actual Microsoft Tech Support person that's willing to offer a more reasonable "professional" response than disconnect the fuse to the house? ... the original profile folders using procedures outlined elsewhere ... the second account's original profile folder is giving me ... It appeared to have been deleted like the first account when I ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: User Account lost when XP had to be reinstalled
    ... you can set XP Home permissions in Safe Mode. ... This is not your administrator account, ... >Open Explorer, go to Tools and Folder Options, on the ... >tab, click advanced, go to the Owner tab and select the ...
    (microsoft.public.windowsxp.accessibility)
  • Re: For those of you who have disabled UAC while using user/admin, you dont have full admin rights &
    ... In Vista, an admin user doesn't have permissions to do everything they did in previous verions of Windows, but still has the ability to take ownership and change permissions. ... Really, all one has to do is add a second user account on the folder or file and give full rights as like the Administrator group, which would be the User account of the user/admin that logs into the machine. ...
    (microsoft.public.windows.vista.general)

Loading