Solved

The permissions on HKEY_CURRENT_USER are incorrectly ordered

Posted on 2010-08-30
7
1,761 Views
Last Modified: 2012-05-10
When I use REGEDT32, and attempt to view the permissions on the CURRENT_USER hive, I recieve the following error  (also see attached screenshot):

The permissions on HKEY_CURRENT_USER are incorrectly ordered, which may cause some entries to be ineffective.  Press OK to continue and sort the permissions correctly, or Cancel to reset the permissions.

I believe that this condition corresponds to the failure of a Group Policy to be applied.
On machines where the registry permissions are "incorrectly ordered", the GPO fails.
The group policy is for Internet Explorer, the DC is Windows 2003, and the target machine is also W2K3.

I have already applied the suggested Microsoft hotfix for this issue (which assigns a new SID), but it did not work.
http://support.microsoft.com/kb/899182

I'm trying to find out if this can be fixed by modifying the permissions on the CURRENT_USERS hive.
Alternatively, I hope to find out if there is anything that can be done in Active directory or the Group Policy, in order to fix the permissions on this hive or allow the Group Policy to write to it.

Thanks!
CURRENT-USER-PERMISSIONS.JPG
0
Comment
Question by:mmahelpdesk
  • 3
  • 3
7 Comments
 
LVL 40

Expert Comment

by:Kyle Abrahams
ID: 33560639
0
 
LVL 40

Expert Comment

by:Kyle Abrahams
ID: 33560655
Disregard, was for something else.
0
 
LVL 40

Expert Comment

by:Kyle Abrahams
ID: 33560689
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 1

Author Comment

by:mmahelpdesk
ID: 33560716
Thanks for asking, but no - XCALCS has not been used.
0
 
LVL 4

Expert Comment

by:vnicolae
ID: 33562271
0
 
LVL 1

Author Comment

by:mmahelpdesk
ID: 33562595
vnicolae,

Thanks for the info... I'll check this out as soon as I can get people logged out.
0
 
LVL 1

Accepted Solution

by:
mmahelpdesk earned 0 total points
ID: 33580967
Microsoft took a look at this issue. The permissions were insufficient for the Everyone group on the CURRENT_USERS hive. Don't know how this got changed in the first place.

Thank for the good tips, everyone!
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolve DNS query failed errors for Exchange
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now