This message was deleted.
# _general
s
This message was deleted.
b
I’ve seen it for old crappy apps that use HKLM for app configuration. Had an app that used c:\appfolder to save application cache that. Was required for app to work properly too. That sucked
👍 1
j
I don't see how that can work period, are you sure the reg values are getting applied at all? Seems like an admin mistake.
👍 1
k
I agree with @Jonathan Pitre unless a custom set of permissions has been configured on that "Worksite" registry key or the user is a local administrator, this shouldn't work
n
GPO user preferences are by default run under the SYSTEM account, now some CSE might impersonate the logged on user. Have you ever noticed the “Run in Logged on user's security context” tick box in the preference? So yes this is possible (or was), though I've personally never used it.
k
@Nathan Sperry is that the case when it's configured in User Configuration?
n
Yes from memory. Look for the tick box I've mentioned above
Otherwise why bother having that tick box
k
Yeah I know about the tick box
Very old but still true I believe
Though as I said never tried to apply HKLM values in the user configuration
k
Well then, I learned something new about group policy today, it's been a while since that happened the last time, thanks 🙂
It wouldn't really make sense, to me at least, to apply HKLM in the user configuration part of GPP
Based in the MS docs this may work though
n
Me neither, I'm trying to forgot GPO’s myself, seen to many environments that are a total mess. My view these days is less is definitely better, now I'm moving to MEM and configuration profiles
💯 1
k
Too many environments are a total mess and I still meet admins who have no or very little knowledge about how GPOs actually work which often end up with "Enforce" being configured on a range of different GPOs
💯 2
And when Loopback Processing is put in the mix, most admins just zone out 😄
⤴️ 1
🤣 2
n
@Ray Davis whilst it is possible, I see no reason to do it like that. In fact I've work in a few law firms now that use that application (iManage) and those settings are always in a Computer based GPO
j
Yeeeeep This is how madness like fslogix rules copy jobs will work in the user context and allow admins to do all sorts of dumb stuff in the user context… it's madness but it works
👍 1
r
@Nathan Sperry How did you know I was working at a Law firm lol. Good eye
n
@Ray Davis cos lots use iManage and in your screen shot you had the registry settings for WorkSite
r
Right, yea. I just don't understand the Logic of putting HKLM under a user. The Run in user logged on security context is set to no. So I don't really understand why it's not applied at the computer GPP side.
🤷‍♂️ 1
Thanks for the collaboration guys. It' always good to have a tech conversation around brainstorming.
👍 2
l
We had to do this for Symantec WSS. It only respected a machine location PAC file, but we had to user user based AD groups, so this way the user config will apply to the machine on user login. It's kind of a pain, but there are times when it is beneficial.