Solved

Group Policy blocking users writing to registry

Posted on 2006-07-18
4
143 Views
Last Modified: 2010-04-18
I am installing a new Samsung Telephone system this weekend.

Along with the phone system is a software package called Office Serv call. In order for Office Serv call to work Samsung tells me in needs to write to the registry when it is opened and it use.

My problem is I have only worked with my company for two months, I never implemented any of the policies which lock down the users so I am struggling to work out where to start.

We are currently on Windows 2003, Active Directory structure, single site, one domain, 100 users of which about 20 will have this software, all clients are using XP.

Any help will be greatly appreciated.
0
Comment
Question by:jstirrup69
  • 2
4 Comments
 
LVL 70

Assisted Solution

by:Chris Dent
Chris Dent earned 125 total points
ID: 17128640

I'm not sure of which policies that will be blocking write access to the registry - although I know it's possible to add keys and such using the Registry setting under Computer Configuration \ Windows Settings \ Security Settings.

However, there are a few things that can help you figure out what's effecting what:

1. Resultant Set of Policy Tool

This runs from any XP or 2003 system by hitting Start, then Run and typing rsop.msc.

2. Group Policy Management Console

Far better than the default tools for managing policies this one also requires XP or 2003 but will give a much nicer view of where policies are applied and exactly what settings are being used. You can download it here:

http://www.microsoft.com/downloads/details.aspx?FamilyID=0a6d4c24-8cbd-4b35-9272-dd3cbfc81887&DisplayLang=en

Sorry it's not more help.

Chris
0
 
LVL 43

Accepted Solution

by:
Steve Knight earned 125 total points
ID: 17128878
Adding to what has been said.  You need to identify from the supplier of the software or your own testing where in the registry it needs to write to.  If the users do not have access to that area then it is easy to add a new group policy object assigned at the top of the OU holding your computers (or at the domain level if you wish) giving a suitable group such as Everyone or Authenticated Users read/write access to the relevant key - the place to find it is as specified by Chris above.    You can't add data to teh registry that way but you it is there to give rights to users so they can access it.


0
 
LVL 43

Expert Comment

by:Steve Knight
ID: 17518719
Sounds good to me.
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question