Solved

File and registry permissions after Workgroup migration to Domain

Posted on 2004-08-18
5
512 Views
Last Modified: 2013-12-04
The issue we are having occurs when we add a Windows 2000 workstation to our new domain that was previously a member of workgroup called "WORKGROUP".

After adding the machine to the domain we reboot, login as domain admin, and find that the file/folder permissions on C: have been reset to "Everyone" with full control. Yet standard domain users have trouble writing to files in the windows folder and other locations on the drive.

The registry shows that "RESTRICTED" and "Everyone" objects have read only access to all areas of the registry. This causes users to have problems with software that write settings to the registry, i.e. AutoCAD or any app that writes into HKLM.

To correct this, we have to login as the domain admin, open regedt32 and add "Domain Users" and "Domain Admins" with full control on the registry, or give "Everyone" and "RESTRICTED" at least read/write access to HKLM.  Then we reset the permissions on the C: drive to make "domainname\Domain Admins" the owner and set "Domain Admins" with full control and "Domain Users" with Change rights in order to straighten things out.

This is a real headache for our helpdesk and it doesn't seem like we should have to do this just to move over to a domain. We're not sure if it has something to do with Group Policies or what. Any help would be greatly appreciated.
0
Comment
Question by:TheITGuy
  • 4
5 Comments
 
LVL 6

Expert Comment

by:Scott_Willcocks
ID: 11839494
we had that problem It is w2k has locked down certain folders

the most important  being %windows% and %system32% this caused us imense problems

Microsoft locked it down to try and combat viruses that copy themselves to the system 32 folder and running.

what we did was to unlock the system 32 folder as this was the cause of most  of the softwarte failing as the programs didn't have the right permissions on dlls to run them.

\\SERVER\SHARE\xcacls.exe c:\winnt\system32\*.* /T /e /g power user:R /y

find xcacls.exe it here

http://www.microsoft.com/windows2000/techinfo/reskit/tools/existing/xcacls-o.asp

then create a shortcut and run this it then adds everyone and assignes full control to every file in the directory you can change the user to power user and add all the domain users to the power user group on all machines.

So anyone authenticated to your domain will gain power user rights on the local machine which is slightly higher than normal users.

Not perfect but it gets around the Autocad problems and other software.

0
 
LVL 6

Expert Comment

by:Scott_Willcocks
ID: 11839500
also try this so have to shortcuts

\\SERVER\SHARE\xcacls.exe c:\winnt\system\*.* /T /e /g power user:R /y

this program needs to be run by an administrator.
0
 
LVL 1

Author Comment

by:TheITGuy
ID: 11871575
Scott,

I used XCACLS.exe on the C:\winnt\system32 folder and it set the permissions the way we need them.  That shortcut should save us a lot of time.

Do you have any suggestions on a quick way to set the registry permissions? Does Microsoft make any kind of utility to reset those as well?

Thanks!
0
 
LVL 6

Expert Comment

by:Scott_Willcocks
ID: 11871655
if you put all users in the power user group you should be ok.

we never had to change those settings as the autocad settings write to HKCU registry key that the user will have the correct rights to write to.

add domain users to the power user group
0
 
LVL 6

Accepted Solution

by:
Scott_Willcocks earned 500 total points
ID: 11871861
you may want to automate the power user thing with this

Set oWshNet = CreateObject("WScript.Network")

sUser = "Domain users"

sNetBIOSDomain = oWshNet.UserDomain
sComputer = oWshNet.ComputerName

Set oGroup = GetObject("WinNT://" & sComputer & "/power users,group")
Set oUser = GetObject("WinNT://" & sNetBIOSDomain & "/" & sUser & ",user")

' suppress errors in case the user is already a member
On Error Resume Next
oGroup.Add(oUser.ADsPath)
On Error Goto 0
'--------------------8<----------------------


It will try to add the user name in the variable "Domain USER"
to the "POWERusers group" group every time the computer boots
up. If the user already exists, the error is suppressed.

If the computers are in another domain than the user you
want to add, you will need to hard code the domain name
the user belongs to in the variable "sNetBIOSDomain".


test this script and add to users logon scripts

0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

This is a guide to the following problem (not exclusive but here) on Windows: Users need our support and we supporters often use global administrative accounts to do this. Using these accounts safely is a real challenge. Any admin who takes se…
In a recent article here at Experts Exchange (http://www.experts-exchange.com/articles/18880/PaperPort-14-in-Windows-10-A-First-Look.html), I discussed my nine-month sandbox testing of the Windows 10 Technical Preview, specifically with respect to r…
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now