PC Review


Reply
Thread Tools Rate Thread

all operations require local admin rights

 
 
EvB
Guest
Posts: n/a
 
      9th Dec 2003
I created a new domain with 2 dc´s and some member servers, all windows
2000. About 50 W2K clients connected.
I use roaming profiles.

1st:
When i logon a client machine the profile loads but when i log off the
profile cannot be saved. This is on all clients with all usernames. When i
give a client local administrator rights it works fine. The userrights on
the profile map on the server are checked and okey.

2nd:
When i try to run local applications on the clients machine the
applications give all sort of errors. When i give the user local admin
rights everything works perfect. This is on al clients with all usernames.

Before I created the new Domain/DC´s this never has been a problem. What can
create the problem that for all actions local administrator rights are
required.

Is it something the DC sents to the client by a group policy or another
security policy? I checked pretty much but can´t find anything. Can anyone
help me out please?

Kind regards,

EvB


 
Reply With Quote
 
 
 
 
Oli Restorick [MVP]
Guest
Posts: n/a
 
      10th Dec 2003
What are the permissions on the share through which the user's profile is
loaded and saved? It sounds like you have only given your users "change"
rather than "full control" and that you have given administrators "full
control". Unfortunately, "full control" is required on profile directories
with Windows 2000 and above. Just giving "change" won't cut it any more.

Hope this helps

Oli

"EvB" <evanbergen(no-spam)@modderkolk(no-spam).nl> wrote in message
news:br43va$mub$(E-Mail Removed)...
> I created a new domain with 2 dc´s and some member servers, all windows
> 2000. About 50 W2K clients connected.
> I use roaming profiles.
>
> 1st:
> When i logon a client machine the profile loads but when i log off the
> profile cannot be saved. This is on all clients with all usernames. When i
> give a client local administrator rights it works fine. The userrights on
> the profile map on the server are checked and okey.
>
> 2nd:
> When i try to run local applications on the clients machine the
> applications give all sort of errors. When i give the user local admin
> rights everything works perfect. This is on al clients with all usernames.
>
> Before I created the new Domain/DC´s this never has been a problem. What

can
> create the problem that for all actions local administrator rights are
> required.
>
> Is it something the DC sents to the client by a group policy or another
> security policy? I checked pretty much but can´t find anything. Can anyone
> help me out please?
>
> Kind regards,
>
> EvB
>
>



 
Reply With Quote
 
EvB
Guest
Posts: n/a
 
      11th Dec 2003
Hi,

All users have full control on the profiles share. The userrights are
inherited to user´s specific profile directories.

I think the fact that profiles cannot be saved is just a small part of some
bigger security problem?

The fact that many apps won´t funcion correct without admin rights is much
worse i think.

Thanks for you help. :-)
"Oli Restorick [MVP]" <(E-Mail Removed)> schreef in bericht
news:(E-Mail Removed)...
> What are the permissions on the share through which the user's profile is
> loaded and saved? It sounds like you have only given your users "change"
> rather than "full control" and that you have given administrators "full
> control". Unfortunately, "full control" is required on profile

directories
> with Windows 2000 and above. Just giving "change" won't cut it any more.
>
> Hope this helps
>
> Oli
>
> "EvB" <evanbergen(no-spam)@modderkolk(no-spam).nl> wrote in message
> news:br43va$mub$(E-Mail Removed)...
> > I created a new domain with 2 dc´s and some member servers, all windows
> > 2000. About 50 W2K clients connected.
> > I use roaming profiles.
> >
> > 1st:
> > When i logon a client machine the profile loads but when i log off

the
> > profile cannot be saved. This is on all clients with all usernames. When

i
> > give a client local administrator rights it works fine. The userrights

on
> > the profile map on the server are checked and okey.
> >
> > 2nd:
> > When i try to run local applications on the clients machine the
> > applications give all sort of errors. When i give the user local admin
> > rights everything works perfect. This is on al clients with all

usernames.
> >
> > Before I created the new Domain/DC´s this never has been a problem. What

> can
> > create the problem that for all actions local administrator rights are
> > required.
> >
> > Is it something the DC sents to the client by a group policy or another
> > security policy? I checked pretty much but can´t find anything. Can

anyone
> > help me out please?
> >
> > Kind regards,
> >
> > EvB
> >
> >

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
all operations require local admin rights EvB Microsoft Windows 2000 Group Policy 4 11th Dec 2003 04:36 PM
all operations require local admin rights EvB Microsoft Windows 2000 Security 2 10th Dec 2003 12:29 PM
all operations require local admin rights EvB Microsoft Windows 2000 Registry 0 9th Dec 2003 09:12 AM
all operations require local admin rights EvB Microsoft Windows 2000 Registry Archive 0 9th Dec 2003 09:12 AM
all operations require local admin rights EvB Microsoft Windows 2000 Active Directory 0 9th Dec 2003 09:11 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 06:15 AM.