Re: User lockout / No desktop/ Tampered registry.

From: Bruce Sanderson (Bruce.Sanderson_at_junk.junk)
Date: 11/02/04


Date: Mon, 1 Nov 2004 17:12:47 -0800

Try applying the default security template (for more info, open Help and
Support, search for security templates):

1. start, run, key mmc /a
2. press Enter
3. click File, Add/Remove Snap-in
4. click Add
5. from the snap-in list, select Security Configuration and Analysis; click
Add; click Close
6. click OK
7. right click on Security and Configuration Analysis in the left pane;
select Open database
8. navigate to any folder (the "database" may not be any use later, so any
"temporary" folder will do)
9. key any name you want for the "database"; click Open
10. on the Import Template panel, select the item called "setup
security.inf"; click Open
11. right click Security Configuration and Analysis in the left pane, select
Configure Computer Now
12. either accept the default log file path, or key the path and file name
of the log file you want the results to be logged in; click OK

-- 
Bruce Sanderson MVP
It's perfectly useless to know the right answer to the wrong question.
"Alphard" <Alphard@discussions.microsoft.com> wrote in message 
news:EE15CCDF-B7DE-42BC-B88C-070F14472A2A@microsoft.com...
>
> A limited user needed greater access to registry so that his program would
> function fully. So just to test i gave the user full access to all the
> branches of the registry. (Was going to remove later so i know it is dumb 
> to
> give permanent acess like that)
> However when i then tried to log on with the mentioned user account, it
> didnt load the desktop. I could Ctrl+alt+del taskmanager and even run
> programs from there, but no desktop.
>
> Trying to solve the problem i could replicate the situation on another
> machine (gave access to all branches with one try). However When I tried 
> it
> third time on third machine, giving access to the branches of the registry 
> 1
> at a time and trying to log on after each change, I ended up with full 
> access
> to entire registry (like first 2 computers) but still able to log on.
>
> One more thing. I created a new low level user account on the problematic
> machine to see if the problem is related with the users group or the 
> specific
> account, and the new user couldn't similarily get the desktop. Whenever i
> raise the privileges of the mentioned users, they will get full desktop 
> and
> everything works.
>
> At this point i am baffled as to what i should do. Maybe someone could 
> give
> me some insight? All 3 computers are:
> Windows XP Proffessional SP2
>
> Thanks in advance 


Relevant Pages

  • Re: My (numerous) Windows Group Policy Issues
    ... I don't have an answer for your issue about the extra settings for SCE ... It sounds maybe like you applied the dc security template to your computer? ... For whatever reason this template and others that came with Windows 2003 ...
    (microsoft.public.windows.group_policy)
  • Re: Tighter security
    ... basically changes ntfs and registry permissions to be that of a power user without ... the extra rights granted to power user. ... > I'm considering applying the compatws security template because I understand I ... > How can I determine the current security template on any given W2k/XP workstation? ...
    (microsoft.public.win2000.security)
  • Re: security Templates
    ... That means the only way to export local policy on XP is to create a security ... Security Templates mmc snapin). ... the machine settings into a security template. ... >>security template exported that way is also empty. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Security Templates vs Group Policy
    ... it does overwrite any settings that were configured in the GPO. ... > security template, will the security template settings override the gpo ...
    (microsoft.public.cert.exam.mcse)
  • RE: Extracting NT password hashes from registry export file
    ... Extracting NT password hashes from registry export file ... This list is provided by the SecurityFocus Security Intelligence Alert Service. ...
    (Pen-Test)