Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Group Policy for Registry Permissions yielding Red X Icon on RSOP

59 views
Skip to first unread message

-

unread,
Feb 18, 2010, 4:57:49 PM2/18/10
to
Greetings,

I'm trying to include registry permissions in my policies to lock down
certain keys. Every single key I select I get a "Red X Icon" on the
registry key and the error message says the following:

"The policy xxxxx resulted in the following error Unknown error. Ofr more
information, see %windir%\security\logs\winlogon.log on the target machine."

Well winlogon.log looks perfectly fine, it isn't complaining about anything.
Further, the permissions on the key did apply successfully.

What gives?


Meinolf Weber [MVP-DS]

unread,
Feb 18, 2010, 5:14:30 PM2/18/10
to

Hello -,

Which OS version, SP/patch level, are you talking about?

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

-

unread,
Feb 18, 2010, 5:42:07 PM2/18/10
to
2003 R2 SP2 and 2008 R2 SP1 all security patches applied. The message is
slightly different on 2008:


"The policy xxxxx resulted in the following error An unknown error occurred
when attempting to open the database.. For more information, see

%windir%\security\logs\winlogon.log on the target machine."

"Meinolf Weber [MVP-DS]" <meiweb@(nospam)gmx.de> wrote in message
news:6cb2911dda9f8...@msnews.microsoft.com...

Meinolf Weber [MVP-DS]

unread,
Feb 19, 2010, 8:29:54 AM2/19/10
to
Hello -,

Do you have any error in the event viewer of the machine where you run rsop?
1090 1091 or 4099? Do you configure the registry settings with Group policy
preferences or with GPO settings under computer configuration?

Also check:
http://support.microsoft.com/kb/955248/en-us

-

unread,
Feb 19, 2010, 4:34:03 PM2/19/10
to
No event log errors and winlogon.log looks ok. the policy is in fact
applying correctly too.


"Meinolf Weber [MVP-DS]" <meiweb@(nospam)gmx.de> wrote in message

news:6cb2911ddad38...@msnews.microsoft.com...

0 new messages