Tech Support > Operating Systems > Windows 2000 > Group Policy only applies to Administrator Group on Profile change
Group Policy only applies to Administrator Group on Profile change
Posted by Michael Curry on August 2nd, 2003


Have a weird problem. Have a generic user set up with very restrictive
group policy and a mandatory roaming profile. The profile was
configured badly when first set up, always boots to "Welcome to
Windows" screen.

If I log in as a the "UserProfile" user and create a new profile, then
copy the profile to the generic user and make it mandatory, the group
policy is not applied to the generic user. If I switch back to the old
profile, its fine.

Security rights for NT are set to allow "Everyone" Read access to the
mandatory user profile. No settings are saved. (Profile is named
UserProfile.MAN and NTUSER.DAT is NTUSER.MAN)

If I add the user to any ADMIN group, Domain Admins for example, the
policy is applied with the new profile. If I then log off and remove
the user from the Admin group, the policies are removed.

Running GPRESULT.EXE on the client gives "FAILED WITH KEY 2" (DOS for
FILE NOT FOUND), under the USER group policy application.

DNS is configured correctly, with the DNS server being the DC (SBS
2000 SP4) and is the first in the list.

I am going crazy with this one, I have done this exact setup many
times before and not had this problem. Anyone have any ideas?

Thanks in advance

Michael Curry

Posted by Curtis Clay III [MSFT] on August 4th, 2003


Change the ntuser.man file back to a .dat file. Make the changes you'll
need to correct the profile. Set it back to .man. This should be easier
than trying to create a new mandatory profile.

"Michael Curry" <mcurry@lortsmith.com> wrote in message
news:96746a2b.0308020420.7df66de4@posting.google.c om...


Posted by Michael Curry on August 5th, 2003


Yes, this certainly works. Any ideas as to what might be causing the
original problem though?

Thanks for your help,

Michael


"Curtis Clay III [MSFT]" <cclay@online.microsoft.com> wrote in message news:<#fgf3ltWDHA.1368@TK2MSFTNGP11.phx.gbl>...


Similar Posts