[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

All new domain users are too restricted

Posted on 2011-03-13
7
Medium Priority
?
415 Views
Last Modified: 2013-11-05
Hi,

new to active directory, I'm trying to create multiple roaming profiles for a homework project. This should be easy enough as I have the instructions right in front of me. But as I'm following them I get stopped by a message when trying to access the computer's properties that says, "This operation has been canceled due to restrictions in effect on this computer..."

How do I remove these restrictions? They seem to be all of over the place and I don't know why. Any users I have created and all new users have heavy restrictions on their accounts. The Administrator account is also restricted. I'm not sure if it's proper but in my school environment I do not have all these restrictions.

Thanks,
Waffe
0
Comment
Question by:waffe
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
7 Comments
 
LVL 8

Expert Comment

by:Acosta Technology Services
ID: 35123675
Check the various group policies in the domain to see if there are restrictions being applied that way.
0
 

Author Comment

by:waffe
ID: 35123774
Thanks,

can you be more specific? I don't know exactly where to modify a GPO of the domain. Is it in Computers and Users or Group Policy Management.
0
 
LVL 8

Assisted Solution

by:PenguinN
PenguinN earned 300 total points
ID: 35123939
Did you already play with GPO's on your domain? (Group Policy Management) of any local policies in this domain?
0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 

Author Comment

by:waffe
ID: 35124147
Yes, I have messed with the GPO of the domain because new users that I created could not logon so I added Domain Users to the allowed log on. I have looked that GPO over extensively for things that would stop me from accessing the computer properties etc but everything seems fine ...

I will look there again...

I could have made other changes earlier in the semester and not remember exactly what I have done, it's all very new to me and I'm still building a frame work for it.


Thanks,
4d
0
 
LVL 8

Accepted Solution

by:
Acosta Technology Services earned 900 total points
ID: 35124589
Check within Group Policy Management and see which GPO's are being applied across the domain.  Another good way to check is by running a "gpresult" from a machine and user account that's having issues, that will give you a list of applied policies for both the user account and the computer object.
0
 
LVL 8

Expert Comment

by:PenguinN
ID: 35125836
See if you can reset your security profile with templates standard installed in windows.
0
 

Author Comment

by:waffe
ID: 35130851
Thanks you two, I did have a GPO on the main domain that I created earlier in the semester. It simply had disabled the control panel. The "gpresult" concept really pointed me in the right direction. Good tool to have.

Thanks,
4D
0

Featured Post

Fill in the form and get your FREE NFR key NOW!

Veeam® is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let's recap what we learned from yesterday's Skyport Systems webinar.
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question