icacls login script

Posted on 2011-04-22
Last Modified: 2012-05-11
I am running Windows 2003 Terminal Servers with roaming profiles.  I inherited the system and have noticed a script runs at login.  It's causing crazy Disk Queue lengths and slowing everyone down as everyone logs into the systems around the same time.  The script is called "RomProfEntSec" and the command line is:

icacls \\server\Profilesharename\%username%.domain /grant *S-1-5-21-790525478-1563985344-1801674531-519:(F) /T

Is there a way to identify who the SID belongs to in my domain?  Is this really necessary to run upon login?  If the user is new, the script runs in a couple seconds.  if you've been here for several years it takes 30+ minutes to touch your entire profile including *.tmp and cookies, etc.  

Question by:supprteng

    Accepted Solution

    I found SIDtoName and was able to determine that the SID belongs to DOMAIN\Enterprise Admins.  Question still remains if I need to grant Enterprise Admins Full rights to everyone's roaming profile upon login.  I don't really see the need to do this...Domain Admins already have full rights to everyone's profile.
    LVL 7

    Expert Comment

    I agree, i don't see the point in it. Even if a group did need to be granted access to everyone's profiles I don't think that would be the best way to do it.

    Author Closing Comment

    Found the Identifier and determined it wasnt needed.

    Featured Post

    Find Ransomware Secrets With All-Source Analysis

    Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

    Join & Write a Comment

    Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
    Microsoft has released remote PowerShell capabilities to all commercial Office 365 customers. So you can be controlled via PowerShell and not from the Office 365 admin center Download Windows PowerShell Module for Lync Online http://www.micros…
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
    Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…

    728 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now