Link to home
Start Free TrialLog in
Avatar of brasso_42
brasso_42

asked on

Error when trying to do system restore on Windows 7 and Vista

I'm getting an error when i'm trying to do a system restore in safe mode on both a Windows 7 and Windows Vista PCs.

Not all privileges or groups referenced are assigned to the caller. (0x80070514)

I've tried running this is both normal mode and safe mode.
I've tried run as administrator
And i've also tried using the local administrator account.
But still get the same error.

Can anyone help.
ASKER CERTIFIED SOLUTION
Avatar of Sebastian Lennskog
Sebastian Lennskog
Flag of Sweden image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Hi,

you will need to make sure that when you select system restore, you right click 'system restore' in start menu and select 'run as administrator' even if you are logged in as a computer admin.

M@
Avatar of Tim Bailen
Tim Bailen

If this computer is in a corporate (domain) environment, there could be an issue with your logon not having the necessary rights that System Restore needs.

I wasn't able to find the most authoritative source, but the best information I could find was on this thread, and it lists that System Restore needs to be running under an account with the following User Rights Assignments:

  • Manage auditing and security log
  • Take ownership of files or other objects
  • Shut down the system
  • Back up files and directories
  • Restore files and directories

You can see which users/groups are granted those rights by opening "Local Security Policy" (secpol.msc /s) and expanding "Local Policies" to open "User Rights Assignment"

Particularly, the issue in my case was that our group policy had removed "Administrators" group from the "Manage auditing and security log" right, and so System Restore gave the "Not all privileges or groups referenced are assigned to the caller. (0x80070514)" error message immediately after choosing a restore point.

As a quick test, if you're able to remove the computer from the domain and then System Restore works, then you can be pretty sure that your Group Policies are interfering.