Mandatory profiles security breach?

From: Renato Martins (renatoalmeidamartins_at_nospam.ibest.com.br)
Date: 06/29/04


Date: Tue, 29 Jun 2004 14:01:48 -0300

Hi all,

should this be treated as a bug in mandatory profiles? After following the
steps outlined in
http://support.microsoft.com/default.aspx?scid=kb;en-us;323368, I log on
with the user having the mandatory profile. Then, I go to the shared folder
where the mandatory profile is located, and rename ntuser.man back to
ntuser.dat. Then, my profile isn't mandatory anymore...

What NTFS permissions should be applied to the ntuser.man file, so the user
can't do this??

Thanks in advance,
Renato