Improve company productivity with a Business Account.Sign Up

x
?
Solved

registry editing has been disabled by your administrator

Posted on 2010-09-01
9
Medium Priority
?
1,459 Views
Last Modified: 2012-05-10
Hi,

I have a domain user (%USER%) that is set as local administration on a specific server(W2K3 R2 std) in my domain.
This user is in a separate OU in the AD. This OU contains a policy that grand the user RDP rights. This works fine.

Now I want the user to be able to edit the registry. Run>regedit
The following error accurse:
"registry editing has been disabled by your administrator"

I have made a new policy for this OU
set:
“Prevent access to registry editing tools” to disable

ran gpupdate & even rebooted the system.

This does not work!

Can anyone help me out?
0
Comment
Question by:sayadi
9 Comments
 
LVL 6

Expert Comment

by:Nuttycomputer
ID: 33576565
You stated the User is in the OU. Is the server also in this OU? If the Server is in an OU that denies editing registry via the Computer Configuration of Group Policy then in the case of conflicting policies Computer Configuration takes precedence over User Policy.
0
 
LVL 12

Expert Comment

by:patrikt
ID: 33576569
Check higher GP objects, because if registry editing is disabled there it gets preference.
In case you have it disabled on root domain GP object you should filter this GP for admins to be able to edit registry.
0
 
LVL 42

Expert Comment

by:Meir Rivkin
ID: 33576582
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 4

Assisted Solution

by:mikesuss
mikesuss earned 600 total points
ID: 33576619
Is there another more restrictive policy that is applying?  You might want to create a temporary admin user to allow the change, then remove the user.  This would more than likely be faster than trying to trouble shoot the registry issue for a one off.
0
 
LVL 2

Author Comment

by:sayadi
ID: 33576647
Under %myDomain.local% there is a OU for the server & a OU for the users on both OU's now I have set this policy and it still does not work!
0
 
LVL 2

Author Comment

by:sayadi
ID: 33576706
The only other policy that is implemented is to prevent the user from a shutdown. they can only logout.
0
 
LVL 6

Accepted Solution

by:
Nuttycomputer earned 1400 total points
ID: 33576803
Sayadi,

Run the RSoP in Logging mode. Select the Server and User in question and that will allow you to see what settings are applying and from what GPOs. Might be able to narrow it down a little easier. See this: http://technet.microsoft.com/en-us/library/cc758010%28WS.10%29.aspx

Also if you set the policy just barely on the servers you need to reboot for it to apply on the servers as computer policies are applied at startup.
0
 
LVL 1

Expert Comment

by:amieldar
ID: 33577530
try to set a new  ou and disable enharit
0
 
LVL 2

Author Comment

by:sayadi
ID: 33584734
It was a confilicting Policy
0

Featured Post

Get 10% Off Your First Squarespace Website

Ready to showcase your work, publish content or promote your business online? With Squarespace’s award-winning templates and 24/7 customer service, getting started is simple. Head to Squarespace.com and use offer code ‘EXPERTS’ to get 10% off your first purchase.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

608 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question