PC Review


Reply
Thread Tools Rate Thread

Default Permissions on HKCU

 
 
Will
Guest
Posts: n/a
 
      28th Jan 2007
Can someone tell me for Windows 2000 and Windows XP, what are the default
permissions on the user's hive tree (HKCU in regedit)? And importantly I
want to know do those permissions inherit from the top of the hive all the
way to the bottom, or are there places in the middle or bottom parts of the
tree that stop inheriting and hardcode their own ACL?

I need to know this in detail to help support movement of profiles from
local to domain users. We have followed the common guidance about the
ProfileList SID entries in HKLM and changing the profile they point to.
This trick has worked perfectly for us for Windows 2003 servers. But on
Windows XP computers we are still missing something. Many times even for
an administrative domain user, the HKLM ProfileList SID changes by adding a
..BAK at the end. Ther domain user login starts to use a Documents &
Settings\TEMP Profile as well. Since the Domain user is being given Full
Control access to the new profile directory in the ACL, I'm suspecting that
the different behavior in XP may be due to some permissions in the ACL for
the registry entries in the user hive stored in the profile directory.

--
Will


 
Reply With Quote
 
 
 
 
Dave Patrick
Guest
Posts: n/a
 
      28th Jan 2007
These two may help.

http://www.microsoft.com/technet/pro....mspx?mfr=true

http://technet2.microsoft.com/Window....mspx?mfr=true

--

Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

"Will" wrote:
> Can someone tell me for Windows 2000 and Windows XP, what are the default
> permissions on the user's hive tree (HKCU in regedit)? And importantly I
> want to know do those permissions inherit from the top of the hive all the
> way to the bottom, or are there places in the middle or bottom parts of
> the
> tree that stop inheriting and hardcode their own ACL?
>
> I need to know this in detail to help support movement of profiles from
> local to domain users. We have followed the common guidance about the
> ProfileList SID entries in HKLM and changing the profile they point to.
> This trick has worked perfectly for us for Windows 2003 servers. But on
> Windows XP computers we are still missing something. Many times even
> for
> an administrative domain user, the HKLM ProfileList SID changes by adding
> a
> .BAK at the end. Ther domain user login starts to use a Documents &
> Settings\TEMP Profile as well. Since the Domain user is being given
> Full
> Control access to the new profile directory in the ACL, I'm suspecting
> that
> the different behavior in XP may be due to some permissions in the ACL for
> the registry entries in the user hive stored in the profile directory.
>
> --
> Will
>
>


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Changing HKCU registry permissions for other user, as Admin. Anteaus Windows XP Security 0 31st Mar 2009 08:47 PM
Setting HKCU register permissions Joris Kemperman Microsoft Windows 2000 Group Policy 1 25th May 2007 03:13 PM
Default Permissions on HKCU Will Windows XP Security 1 28th Jan 2007 03:00 PM
Change permissions on HKCU registry keys using group policy? ruth@redelf.co.uk Windows XP Help 0 21st Dec 2006 02:28 PM
Setting permissions on HKCU\Control Panel\Current barabba Microsoft Windows 2000 Group Policy 5 30th Dec 2003 06:51 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 08:21 PM.