Re: Applied a security policy to standalone XP and strange outcome

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 03/16/05


Date: Wed, 16 Mar 2005 07:02:22 -0700

There are so, so many possibilites.
While local security policy does not allow Restricted Group
definitions, these however can be defined in a SCE template,
and when such a template is applied to a standalone system
these will have a one-time effect on the target system.
A Restricted Group definition can be used to state the precise
membership in and also of a Windows group.
Perhaps you wandered into this territory (?).

-- 
Roger Abell
Microsoft MVP (Windows  Security)
MCSE (W2k3,W2k,Nt4)  MCDBA
"Gringo" <bkey89@msn.com> wrote in message
news:1110978711.942125.55550@g14g2000cwa.googlegroups.com...
> First of all let me say that this is my first time ever posting to a
> group of any kind so please be forgiving with my inexperience. After
> many years I am changing career fields and going into IT.
>
> Here's my situation...
>
> I have an XPpro stand-alone machine that I was messing around with on
> Snap-ins and the Security Analysis and Configuration.  I don't remember
> exactly but 99% confident that I imported and applied the Hisec
> template.
>
> Before the template was applied my user account was the local admin
> account (which was set as admin from the start when I installed XP on
> the machine)and I had 2 other limited user accounts plus 1 guest
> account, all of which showed up on the Welcome screen.
>
> After I logged off I noticed that my user did not show up on the
> welcome screen and neither did the guest account, instead, a
> "Administrator" user appeared with the two limited user accounts on the
> Welcome screen.  I clicked to logon as the admin but was unable due to
> not having the correct password (I have no clue what it would be
> because I never setup and "Administrator" user for the machine.
>
> So I began freaking-out and rebooted the system; now the welcome screen
> only shows the two limited user accounts and that's it.  Through
> reading this group I found that I could press ctrl-alt-delete twice and
> get the network login, which I did, and logged in with my user account
> name no problem.  HOWEVER, my user account is no longer set as an admin
> account and I can't even view my system calendar much less anything
> else.
>
> I downloaded an image to make a boot cd to reset the admin password, I
> will see if it works this evening, but I was wondering if anyone knows
> what would cause my user to be "kicked out" of the admin group on a
> stand alone machine???
>
> Thanks again for the help and forgive me for being long winded and a
> newbie.
>


Relevant Pages

  • Re: Applied a security policy to standalone XP and strange outcome
    ... The hisecure template for workstations will remove all users from the local ... account the password reset disk you mention to regain admin access to your ... For future reference you can view the security template in the mmc ...
    (microsoft.public.win2000.security)
  • Re: Need help closing security holes in my Windows XP home system!
    ... really, stop using the win xp user account with admin, that makes it ... Look you ignorant moron, I've been using computers for nearly 25 years, ... and not security issues, which goes against the entire world's opinion ... Admin rights, ...
    (comp.security.firewalls)
  • Re: secured db, yet insecure with alternate worgroup file..
    ... Did you check ownership of the "Database" object? ... left as "Admin" by people setting up security who don't know what they're doing. ... If a user account "owns" the database then they can open the file regardless of ...
    (microsoft.public.access.security)
  • Re: linksys media center extender installation error
    ... Is the user account that you're running on the PC a member of the ... Clear all events from the system, security, and application event viewer ... 1:13:28 PM: Verifying Privacy Policy is present. ... 1:13:51 PM: Verifying MCRD users group exists. ...
    (microsoft.public.windows.mediacenter)
  • Re: Problem when creating news users
    ... Remote Web Workplace Users ... Entering the Template Committer... ... User account: Klazina created successfully. ... management console, and although i gave them an e-mail adres, when i click ...
    (microsoft.public.windows.server.sbs)