Right now I am removing admin rights from all machines on the domain so as to cut down on spyware and unwanted software.
I log into the remote machines with VNC then log in as local admin, remove the domain profile from local admin group and add them to user group. When I log them back in none of my group policys are working, they are there, they just aren’t working. I run rsop.msc and it shows all of the policies, they just aren’t applying. I can tell this because one of the policies is force classic start menu.
The only fix that I have found so far is to rename the profile and log back in with the user then copy the old profile into the new profile, however this is very slow when you are doing it to 300+ machines remotely.
Any help is appreciated.