Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

All new domain users are too restricted

Posted on 2011-03-13
7
409 Views
Last Modified: 2013-11-05
Hi,

new to active directory, I'm trying to create multiple roaming profiles for a homework project. This should be easy enough as I have the instructions right in front of me. But as I'm following them I get stopped by a message when trying to access the computer's properties that says, "This operation has been canceled due to restrictions in effect on this computer..."

How do I remove these restrictions? They seem to be all of over the place and I don't know why. Any users I have created and all new users have heavy restrictions on their accounts. The Administrator account is also restricted. I'm not sure if it's proper but in my school environment I do not have all these restrictions.

Thanks,
Waffe
0
Comment
Question by:waffe
  • 3
  • 2
  • 2
7 Comments
 
LVL 8

Expert Comment

by:Acosta Technology Services
ID: 35123675
Check the various group policies in the domain to see if there are restrictions being applied that way.
0
 

Author Comment

by:waffe
ID: 35123774
Thanks,

can you be more specific? I don't know exactly where to modify a GPO of the domain. Is it in Computers and Users or Group Policy Management.
0
 
LVL 8

Assisted Solution

by:PenguinN
PenguinN earned 75 total points
ID: 35123939
Did you already play with GPO's on your domain? (Group Policy Management) of any local policies in this domain?
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Author Comment

by:waffe
ID: 35124147
Yes, I have messed with the GPO of the domain because new users that I created could not logon so I added Domain Users to the allowed log on. I have looked that GPO over extensively for things that would stop me from accessing the computer properties etc but everything seems fine ...

I will look there again...

I could have made other changes earlier in the semester and not remember exactly what I have done, it's all very new to me and I'm still building a frame work for it.


Thanks,
4d
0
 
LVL 8

Accepted Solution

by:
Acosta Technology Services earned 225 total points
ID: 35124589
Check within Group Policy Management and see which GPO's are being applied across the domain.  Another good way to check is by running a "gpresult" from a machine and user account that's having issues, that will give you a list of applied policies for both the user account and the computer object.
0
 
LVL 8

Expert Comment

by:PenguinN
ID: 35125836
See if you can reset your security profile with templates standard installed in windows.
0
 

Author Comment

by:waffe
ID: 35130851
Thanks you two, I did have a GPO on the main domain that I created earlier in the semester. It simply had disabled the control panel. The "gpresult" concept really pointed me in the right direction. Good tool to have.

Thanks,
4D
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Resolve DNS query failed errors for Exchange
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question