[Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

The permissions on HKEY_CURRENT_USER are incorrectly ordered

Posted on 2010-08-30
7
Medium Priority
?
1,900 Views
Last Modified: 2012-05-10
When I use REGEDT32, and attempt to view the permissions on the CURRENT_USER hive, I recieve the following error  (also see attached screenshot):

The permissions on HKEY_CURRENT_USER are incorrectly ordered, which may cause some entries to be ineffective.  Press OK to continue and sort the permissions correctly, or Cancel to reset the permissions.

I believe that this condition corresponds to the failure of a Group Policy to be applied.
On machines where the registry permissions are "incorrectly ordered", the GPO fails.
The group policy is for Internet Explorer, the DC is Windows 2003, and the target machine is also W2K3.

I have already applied the suggested Microsoft hotfix for this issue (which assigns a new SID), but it did not work.
http://support.microsoft.com/kb/899182

I'm trying to find out if this can be fixed by modifying the permissions on the CURRENT_USERS hive.
Alternatively, I hope to find out if there is anything that can be done in Active directory or the Group Policy, in order to fix the permissions on this hive or allow the Group Policy to write to it.

Thanks!
CURRENT-USER-PERMISSIONS.JPG
0
Comment
Question by:mmahelpdesk
  • 3
  • 3
7 Comments
 
LVL 41

Expert Comment

by:Kyle Abrahams
ID: 33560639
0
 
LVL 41

Expert Comment

by:Kyle Abrahams
ID: 33560655
Disregard, was for something else.
0
 
LVL 41

Expert Comment

by:Kyle Abrahams
ID: 33560689
0
Veeam Disaster Recovery in Microsoft Azure

Veeam PN for Microsoft Azure is a FREE solution designed to simplify and automate the setup of a DR site in Microsoft Azure using lightweight software-defined networking. It reduces the complexity of VPN deployments and is designed for businesses of ALL sizes.

 
LVL 1

Author Comment

by:mmahelpdesk
ID: 33560716
Thanks for asking, but no - XCALCS has not been used.
0
 
LVL 4

Expert Comment

by:vnicolae
ID: 33562271
0
 
LVL 1

Author Comment

by:mmahelpdesk
ID: 33562595
vnicolae,

Thanks for the info... I'll check this out as soon as I can get people logged out.
0
 
LVL 1

Accepted Solution

by:
mmahelpdesk earned 0 total points
ID: 33580967
Microsoft took a look at this issue. The permissions were insufficient for the Everyone group on the CURRENT_USERS hive. Don't know how this got changed in the first place.

Thank for the good tips, everyone!
0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

865 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question