I have a basic new installation W2K server with AD, created a Domain User & a Domain Local Group, put my user in the group, went into Default Domain Policy & edited it as follows: User Configuration – Windows Settings – Scripts – Logon properties, Browsed & Added a batch file that simply maps a network share. Added my group to the security list of the Default Domain Policy & made sure the READ & APPLY GROUP POLICY permissions were ticked. My user has rights to the shared folder being mapped by the login script. User is in the default Users folder/container. Any ideas on why the script doesn’t run? I works if I assign it directly to each individual user (selecting the user – Properties – Profile – Logon Script & entering the batch filename). Please help.