In Windows XP SP3, how can I remove "ALL Programs" in the Start Menu for a user on the computer?

In Windows XP Professional - SP3, I have set up a "user" on a Dell laptop.  I want the user to have very limited access.  Mostly with items on the desktop.  I want to remove the "All Programs" on the Start Menu, so that the user will not have access to it.

I want the administrator account to have full access.

I found a registry fix, but I cannot get it to work with the "user".  I can do it for the administrator account, but not the user.

Windows Registry Editor Version 5.00
 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoStartMenuMorePrograms"=dword:00000001

When I try to import the fix while in the user account a Registry Editor error appears...
"Cannot import "fix.reg: Not all data was successfully written to the registry.  Some keys are open by the system or other processes."  Tried in SAFE MODE as well, but same result.

Again, logged in as administrator, it will work.  Once I restart the "All Programs" is gone.  However, if I log in as the "user', "All Programs" is still there.

Can someone give me some advice.  It would be greatly appreciated.

Thanks!
mbolton1967Asked:
Who is Participating?
 
TripyreConnect With a Mentor Commented:
have you limited the access for the "user" account.  This may be why you cannot import the registry setting.  Give the "User" account temporary Admin access, import the registry setting, remove the access and logout and back in with "User" account.  The change should have stuck.
0
 
DarksquireCommented:
Click Start, Run, type gpedit.msc then confirm with the Enter key. Go to User Configuration => Administrative Templates => Start menu and Taskbar.

Double click Remove All Programs list in the Start menu and select On. Then click OK.

Try this logged into the Administrator account and reboot into user account to see if it works. If it is still there, I would go through the steps again while logged into the user account and then reboot back into that account. That should do the trick. Hope that helps!
0
 
johnb6767Commented:
Even an Admin doesnt have rights to thier own "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies". Thats where GPO is stored. You need to explicitly grant Modify Rights to the above key.....
0
Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

 
darkchild173Commented:
You can access that key by logging as an administrator.
Find out the SID of the account you are trying to fix. Here's how:

Open regedit and goto:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\Cu rrentVersion\ProfileList

Click on any of key on the left [SID] and check out the right pane for ProfileImagePath. Now you should find something as following there:

%SystemDrive%\Documents and Settings\username

Do that untill you find the right SID.

Now, that you know the SID of the acount, in regedit, instead of going to
HKEY_CURRENT_USER\..  just goto HKEY_USERS\SID\... and modify the settings accordingly.

While i understand what you are trying to accomplish, please bare in mind that any program that allows the user to open a browse window to the file system (e.g. Internet Explorer), also allows him to execute programs, so technically you're not restricting the user unless you also explicity deny him access to the files, by means of ACL's, but when u get to restricting access to folders like "Program Files" you get into a world of pain.

You might want to look into different approaches on this, something along the lines of this:
http://technet.microsoft.com/en-us/library/bb457006.aspx

Good luck.
0
 
mbolton1967Author Commented:
Thanks so much for the help.
0
 
johnb6767Commented:
Clarification.....

"Even an Admin doesnt have rights to thier own "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies". "

They do have the rights to grant themself permissions though....
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.