Vista SP1 User's Group Policy In vista sp1 i want to let users to control the display settings through Personalization of Control panel.<br>Can you tell wich files do i have to permit through user's group policy in <strong>System</strong> (Run only allowed Windows programs)?© 2009 Microsoft Corporation. All rights reserved.Fri, 03 Jul 2009 04:27:22 Z214b9127-aa41-4c32-83c1-2c54707b4190http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/214b9127-aa41-4c32-83c1-2c54707b4190#214b9127-aa41-4c32-83c1-2c54707b4190http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/214b9127-aa41-4c32-83c1-2c54707b4190#214b9127-aa41-4c32-83c1-2c54707b4190Nautoshttp://social.technet.microsoft.com/Profile/en-US/?user=NautosVista SP1 User's Group Policy In vista sp1 i want to let users to control the display settings through Personalization of Control panel.<br>Can you tell wich files do i have to permit through user's group policy in <strong>System</strong> (Run only allowed Windows programs)?Thu, 05 Jun 2008 15:32:04 Z2008-06-05T15:32:04Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/214b9127-aa41-4c32-83c1-2c54707b4190#3f7ee5ff-6267-4838-89df-bfa0e60b6343http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/214b9127-aa41-4c32-83c1-2c54707b4190#3f7ee5ff-6267-4838-89df-bfa0e60b6343Miles Lihttp://social.technet.microsoft.com/Profile/en-US/?user=Miles%20LiVista SP1 User's Group Policy<span style="color:#1f497d"><font size=2><font face=Verdana>Hello,</font></font></span> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font face=Verdana size=2> </font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font size=2><font face=Verdana>By default, both local and domain standard users have the permission to access and change the Display Settings. I'd like to know whether you receive the &quot;Your system administrator has disabled lunching of the Display settings control panel&quot; message when trying to open Display Setting dialog. If yes, try to check the following policy setting.</font></font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font face=Verdana size=2> </font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font size=2><font face=Verdana>User Configuration---&gt;Administrative Template---&gt;Control Panel---&gt;Display---&gt;Hide settings tab</font></font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font face=Verdana size=2> </font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font size=2><font face=Verdana>You can run &quot;gpresult /v&quot; to verify the current applied group policy settings.</font></font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font face=Verdana size=2> </font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font size=2><font face=Verdana>Is there anything I have missed?</font></font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font face=Verdana size=2> </font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font face=Verdana size=2> </font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font face=Verdana size=2> </font></span></p>Fri, 06 Jun 2008 07:19:11 Z2008-06-06T07:19:11Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/214b9127-aa41-4c32-83c1-2c54707b4190#4ad63137-52dd-4f33-b842-059e698986cehttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/214b9127-aa41-4c32-83c1-2c54707b4190#4ad63137-52dd-4f33-b842-059e698986ceNautoshttp://social.technet.microsoft.com/Profile/en-US/?user=NautosVista SP1 User's Group PolicyThanks for your concern.<br> The &quot;Hide Setting Tab&quot; is Disabled.<br>I have enabled in User Configuration --&gt; Administrative Templates --&gt; System --&gt; Run only allowed Windows applications.<br>Although that i have inserted the executables that i found out with the help of Process Explorer of Sysinternals , i still get the message that It is not permitted because of the effective permissions and i have to contact the administrator.<br>When i disable the Run only allowed Windows applications then everything is OK.<br>I really stacked on that problem for three days now and i do not know what to do.<br>Things are much simpler with XP!<br>But with Vista everything  is safer for the average user but when it comes the time for &quot;fine tuning&quot; then the administrator is in trouble...<br>Yes i have checked the gpo with &quot;gpresult /v&quot; and is applied correctly.Fri, 06 Jun 2008 13:56:25 Z2008-06-06T14:01:15Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/214b9127-aa41-4c32-83c1-2c54707b4190#c21eeccc-08fe-492b-ab46-8b1e060acf61http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/214b9127-aa41-4c32-83c1-2c54707b4190#c21eeccc-08fe-492b-ab46-8b1e060acf61Miles Lihttp://social.technet.microsoft.com/Profile/en-US/?user=Miles%20LiVista SP1 User's Group Policy<font size=4> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font style="font-size:12px">Hello,</font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font style="font-size:12px"> </font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font style="font-size:12px">I perform the test on my side and reproduce the issue of accessing and changing Personalization settings (Desktop background, sounds, display settings and etc) when &quot;Run only specified windows application&quot; policy settings is enabled.</font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font style="font-size:12px"> </font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font style="font-size:12px">From my research, it seems to result from the change of the Explorer and control panel in the Windows Longhorn operating system. Application executing restriction via &quot;Run only specified windows application&quot; is weak because it only the put the restriction on the Explorer.exe (default shell). In the other word, the restriction will not function when you use CMD.exe to execute applications. Then I'd like to introduce you to use the Software Restriction Policy to implement application restriction on client and it is safe to Personalization settings.</font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font style="font-size:12px"> </font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font style="font-size:12px">To have the same effect as the &quot;Run only specified windows application&quot;, you may create a Hash Rule with Disallowed as the default security level.</font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font style="font-size:12px"> </font></span></p> <p style="margin:0in 0in 0pt 0.5in"><span style="color:#1f497d"><font style="font-size:11px"><font style="font-size:12px"><span><font style="font-size:12px">1.</font><span style="font:7pt 'Times New Roman'"><font style="font-size:12px" face=Verdana>    </font></span></span><span style="color:#1f497d"><font style="font-size:12px">In a Group Policy object, right click the Software Restriction Policies (User configuration---&gt;Windows Settings---&gt;Security Settings) and click New Software Restriction Policies.</font></span></font></font></p> <p style="margin:0in 0in 0pt 0.5in"><span style="color:#1f497d"><font style="font-size:11px"><font style="font-size:12px"><span><font style="font-size:12px">2.</font><span style="font:7pt 'Times New Roman'"><font style="font-size:12px" face=Verdana>    </font></span></span><span style="color:#1f497d"><font style="font-size:12px">In the Security Levels, right click Disallowed and set is as default.</font></span></font></font></p> <p style="margin:0in 0in 0pt 0.5in"><span style="color:#1f497d"><font style="font-size:11px"><font style="font-size:12px"><span><font style="font-size:12px">3.</font><span style="font:7pt 'Times New Roman'"><font style="font-size:12px" face=Verdana>    </font></span></span><span style="color:#1f497d"><font style="font-size:12px">In the Additional rules, create new hash rules for allowed specific programs.</font></span></font></font></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font style="font-size:12px"> </font></span></p> <p style="margin:0in 0in 0pt"><span style="color:#1f497d"><font style="font-size:12px">Hope it helps.</font></span></p></span></span></span></font>Thu, 12 Jun 2008 02:31:16 Z2008-06-12T02:31:16Zhttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/214b9127-aa41-4c32-83c1-2c54707b4190#0ee93f62-9322-44bf-84a6-0e982a82e6achttp://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/214b9127-aa41-4c32-83c1-2c54707b4190#0ee93f62-9322-44bf-84a6-0e982a82e6acThe lost Adminhttp://social.technet.microsoft.com/Profile/en-US/?user=The%20lost%20AdminVista SP1 User's Group PolicyWe are experiencing the same issue here. <div><br/></div> <div><span style="white-space:pre"> </span>We are using <span style="white-space:pre"> </span>Windows 2003 Enterprise Sp2 <span style="white-space:pre"> </span> (domain Controller)</div> <div><span style="white-space:pre"> </span>Windows <span style="white-space:pre"> </span>Vista Business Sp1<span style="white-space:pre"> </span> (workstation)<br/></div> <div><br/></div> <div>We start by creating a fresh group and a fresh user, then apply the Group Policy setting <strong>Run only allowed Windows applications</strong>.<strong>  </strong>We have not enabled or disabled any of the other Group Policy settings!</div> <div><br/></div> <div>We then log-on to the Vista machine and the <strong>3D Aero Glass</strong> setting is disabled.  We right click the desk top and select <strong>Personalize</strong> and then try to select <strong>Windows Color and Appearance</strong> and then we get the following error message:</div> <div><br/></div> <div><span style="white-space:pre"> </span><strong>Restrictions - This operation has been cancelled due to the restrictions in effect on this computer.  Please contact your system administrator.</strong></div> <div><strong><br/></strong></div> <div>We get the same error message for all of the settings on the Personalization page <strong>except for Desktop Background</strong> setting, which opens and functions just fine.</div> <div><br/></div> <div>Does anyone have any suggestions to help end the <strong>MADNESS</strong>?</div> <div><br/></div> <div>   Lost,</div> <div><br/></div> <div>   The System Administrator</div>Fri, 03 Jul 2009 04:27:22 Z2009-07-03T04:27:22Z