• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 623
  • Last Modified:

icacls login script

I am running Windows 2003 Terminal Servers with roaming profiles.  I inherited the system and have noticed a script runs at login.  It's causing crazy Disk Queue lengths and slowing everyone down as everyone logs into the systems around the same time.  The script is called "RomProfEntSec" and the command line is:

icacls \\server\Profilesharename\%username%.domain /grant *S-1-5-21-790525478-1563985344-1801674531-519:(F) /T

Is there a way to identify who the SID belongs to in my domain?  Is this really necessary to run upon login?  If the user is new, the script runs in a couple seconds.  if you've been here for several years it takes 30+ minutes to touch your entire profile including *.tmp and cookies, etc.  

  • 2
1 Solution
supprtengAuthor Commented:
I found SIDtoName and was able to determine that the SID belongs to DOMAIN\Enterprise Admins.  Question still remains if I need to grant Enterprise Admins Full rights to everyone's roaming profile upon login.  I don't really see the need to do this...Domain Admins already have full rights to everyone's profile.
I agree, i don't see the point in it. Even if a group did need to be granted access to everyone's profiles I don't think that would be the best way to do it.
supprtengAuthor Commented:
Found the Identifier and determined it wasnt needed.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Cloud Class® Course: Microsoft Office 2010

This course will introduce you to the interfaces and features of Microsoft Office 2010 Word, Excel, PowerPoint, Outlook, and Access. You will learn about the features that are shared between all products in the Office suite, as well as the new features that are product specific.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now