<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Supporto Tecnico Enterprise : Restricted Group</title><link>http://blogs.technet.com/itasupport/archive/tags/Restricted+Group/default.aspx</link><description>Tags: Restricted Group</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Restricted Group - Problemi con l’applicazione delle Group Policy</title><link>http://blogs.technet.com/itasupport/archive/2009/04/27/restricted-group-problemi-con-l-applicazione-delle-group-policy.aspx</link><pubDate>Mon, 27 Apr 2009 02:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3229159</guid><dc:creator>itentblg</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/itasupport/comments/3229159.aspx</comments><wfw:commentRss>http://blogs.technet.com/itasupport/commentrss.aspx?PostID=3229159</wfw:commentRss><description>&lt;p&gt;In questo post approfondiremo i possibili problemi che si possono verificare nell’&lt;strong&gt;&lt;a href="http://blogs.technet.com/itasupport/archive/2009/04/13/restricted-group-funzionalit-e-applicazione.aspx" target="_blank"&gt;applicazione dei Restricted Group tramite Group Policy&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;  &lt;h3&gt;Problema&lt;/h3&gt;  &lt;p&gt;Quando si presenta il problema durante il boot la configurazione del &lt;strong&gt;Restricted Group&lt;/strong&gt; non è applicata completamente ed è creato un evento &lt;strong&gt;SceCli 1001&lt;/strong&gt;:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;Event ID&amp;#160;&amp;#160;&amp;#160;&amp;#160; : 1001        &lt;br /&gt;&lt;/strong&gt;Category&amp;#160;&amp;#160;&amp;#160;&amp;#160; : None       &lt;br /&gt;&lt;strong&gt;Source&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; : SceCli        &lt;br /&gt;&lt;/strong&gt;Type&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; : Error       &lt;br /&gt;Generated&amp;#160;&amp;#160;&amp;#160; : 11/10/2008 5:27:44 AM       &lt;br /&gt;Written&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; : 11/10/2008 5:27:44 AM       &lt;br /&gt;Machine&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; : W010010312       &lt;br /&gt;&lt;strong&gt;Message&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; : Security policy cannot be propagated. Impossibile eliminare la cache dei criteri di gruppo.&lt;/strong&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;Considerando come funziona l’applicazione dei &lt;strong&gt;Restricted Group, &lt;a href="http://blogs.technet.com/itasupport/archive/2009/04/13/restricted-group-funzionalit-e-applicazione.aspx" target="_blank"&gt;leggi il precedente post&lt;/a&gt;&lt;/strong&gt;, ho ipotizzato che il problema fosse causato da un &lt;strong&gt;lock&lt;/strong&gt; sul file &lt;strong&gt;tmpgptfl.inf&lt;/strong&gt;. Per avere una conferma alla mia ipotesi ho abilitato l’audit sui tutti i file e cartelle sotto la cartella &lt;strong&gt;C:\Windows\Security\Templates &lt;/strong&gt;avendo una conferma alla mia idea. Infatti l’evento &lt;strong&gt;560&lt;/strong&gt; mostra che il processo con PID &lt;strong&gt;2972&lt;/strong&gt; “tocca” il file tenendolo “bloccato”.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Event ID&amp;#160;&amp;#160;&amp;#160;&amp;#160; : 560      &lt;br /&gt;Source&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; : Security       &lt;br /&gt;Type&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; : Audit Success       &lt;br /&gt;Generated&amp;#160;&amp;#160;&amp;#160; : 11/10/2008 5:27:44 AM       &lt;br /&gt;Written&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; : 11/10/2008 5:27:44 AM       &lt;br /&gt;Machine&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; : MBXP       &lt;br /&gt;Message&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; : Object Open:       &lt;br /&gt;&amp;#160;&amp;#160; Object Server:&amp;#160;&amp;#160; Security       &lt;br /&gt;&amp;#160;&amp;#160; Object Type:&amp;#160;&amp;#160; File       &lt;br /&gt;&lt;strong&gt;&amp;#160;&amp;#160; Object Name:&amp;#160;&amp;#160; C:\WINNT\security\templates\policies\tmpgptfl.inf&lt;/strong&gt;       &lt;br /&gt;&amp;#160;&amp;#160; Handle ID:&amp;#160;&amp;#160; -2147478420       &lt;br /&gt;&amp;#160;&amp;#160; Operation ID:&amp;#160;&amp;#160; {0,207111}       &lt;br /&gt;&lt;strong&gt;&amp;#160;&amp;#160; Process ID:&amp;#160;&amp;#160; 2972        &lt;br /&gt;&lt;/strong&gt;&amp;#160;&amp;#160; Image File Name:&amp;#160;&amp;#160; &lt;br /&gt;&amp;#160;&amp;#160; Primary User Name:&amp;#160;&amp;#160; MBXP$       &lt;br /&gt;&amp;#160;&amp;#160; Primary Domain:&amp;#160;&amp;#160; DISNEY       &lt;br /&gt;&amp;#160;&amp;#160; Primary Logon ID:&amp;#160;&amp;#160; (0x0,0x3E7)       &lt;br /&gt;&amp;#160;&amp;#160; Client User Name:&amp;#160;&amp;#160; -       &lt;br /&gt;&amp;#160;&amp;#160; Client Domain:&amp;#160;&amp;#160; -       &lt;br /&gt;&amp;#160;&amp;#160; Client Logon ID:&amp;#160;&amp;#160; -       &lt;br /&gt;&amp;#160;&amp;#160; Accesses:&amp;#160;&amp;#160; %%4416&amp;#160; &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; %%4423       &lt;br /&gt;&amp;#160; Privileges:&amp;#160;&amp;#160; -       &lt;br /&gt;&amp;#160;&amp;#160; Restricted Sid Count:&amp;#160;&amp;#160; 0       &lt;br /&gt;&amp;#160;&amp;#160; Access Mask:&amp;#160;&amp;#160; Security8 &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Il &lt;strong&gt;PID&lt;/strong&gt; è elevato (2972) e non è sicuramente quello del processo &lt;strong&gt;Winlogon&lt;/strong&gt;. Aprendo task manager scopro che il processo con il PID 2972 è &lt;strong&gt;ALG.exe&lt;/strong&gt; ovvero &lt;strong&gt;Application Layer Gateway Service&lt;/strong&gt;. Questo processo non dovrebbe andare a leggere questi file e quindi è inspiegabile come mai questi file siano letti e soprattutto messi in lock rendendoli illeggibili dal processo &lt;strong&gt;Winlogon&lt;/strong&gt; per l’applicazione delle policy.&lt;/p&gt;  &lt;p&gt;Con process monitor, configurandolo per collezionare i dati durante il boot, il sistema ha tracciato l’accesso ai file sotto la cartella &lt;strong&gt;“C:\WINNT\security\templates\policies”. &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Il log di Process Monitor mostra che il processo &lt;b&gt;ALG.exe&lt;/b&gt; accede ad un notevole numero di file e cartelle. Tra le cartelle che sono aperte dal processo &lt;b&gt;ALG.exe&lt;/b&gt; c’è anche la cartella &lt;b&gt;C:\WINNT\SECURITY\TEMPLATES\POLICIES &lt;/b&gt;e tutti i file contenuti in essa e quindi anche il file &lt;b&gt;TMPGPTFL.INF.&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;Qui sotto la sequenza del &lt;b&gt;process monitor&lt;/b&gt; log:&lt;/p&gt;  &lt;p&gt;&lt;i&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;strong&gt;13:34:41.1974394 alg.exe 3384&lt;/strong&gt; QueryDirectory C:\WINNT\security SUCCESS 0: ., 1: .., 2: Database, 3: logs, 4: templates...       &lt;br /&gt;&lt;strong&gt;13:34:41.2118214 alg.exe 3384 &lt;/strong&gt;CreateFile C:\WINNT\security\TEMPLATES SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened...       &lt;br /&gt;&lt;strong&gt;13:34:41.2317561 alg.exe 3384&lt;/strong&gt; CreateFile C:\WINNT\security\templates\policies SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened       &lt;br /&gt;&lt;strong&gt;13:34:41.2379169 alg.exe 3384&lt;/strong&gt; QueryDirectory C:\WINNT\security\templates\policies SUCCESS 0: ., 1: .., 2: gpt00000.dom, 3: gpt00001.inf, 4: gpt00002.inf, 5: tmpgptfl.inf       &lt;br /&gt;&lt;strong&gt;13:34:41.2380052 alg.exe 3384&lt;/strong&gt; QueryDirectory C:\WINNT\security\templates\policies NO MORE FILES       &lt;br /&gt;&lt;strong&gt;13:34:41.2380490 alg.exe 3384 &lt;/strong&gt;CloseFile C:\WINNT\security\templates\policies SUCCESS       &lt;br /&gt;&lt;strong&gt;13:34:42.6791166 alg.exe 3384 &lt;/strong&gt;CreateFile C:\WINNT\security\templates\policies\tmpgptfl.inf SUCCESS Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened       &lt;br /&gt;&lt;strong&gt;13:34:42.6817174 alg.exe 3384&lt;/strong&gt; QueryStandardInformationFile C:\WINNT\security\templates\policies\tmpgptfl.inf SUCCESS AllocationSize: 144, EndOfFile: 142, NumberOfLinks: 1, DeletePending: False, Directory: False       &lt;br /&gt;13:34:42.7097160 alg.exe 3384 CreateFile C:\WINNT\security\templates\policies\gpt00000.dom SUCCESS Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened       &lt;br /&gt;13:34:42.7177564 alg.exe 3384 QueryStandardInformationFile C:\WINNT\security\templates\policies\gpt00000.dom SUCCESS AllocationSize: 2,048, EndOfFile: 1,822, NumberOfLinks: 1, DeletePending: False, Directory: False       &lt;br /&gt;13:34:42.7609479 alg.exe 3384 CreateFile C:\WINNT\security\templates\policies\gpt00001.inf SUCCESS Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened       &lt;br /&gt;13:34:42.7613351 alg.exe 3384 QueryStandardInformationFile C:\WINNT\security\templates\policies\gpt00001.inf SUCCESS AllocationSize: 5,120, EndOfFile: 4,638, NumberOfLinks: 1, DeletePending: False, Directory: False       &lt;br /&gt;13:34:42.7811776 alg.exe 3384 CreateFile C:\WINNT\security\templates\policies\gpt00002.inf SUCCESS Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened       &lt;br /&gt;13:34:42.7953439 alg.exe 3384 QueryStandardInformationFile C:\WINNT\security\templates\policies\gpt00002.inf SUCCESS AllocationSize: 1,536, EndOfFile: 1,282, NumberOfLinks: 1, DeletePending: False, Directory: False       &lt;br /&gt;13:34:44.6352280 alg.exe 3384 CloseFile C:\WINNT\security\templates\policies\tmpgptfl.inf SUCCESS       &lt;br /&gt;13:34:44.6376565 alg.exe 3384 CloseFile C:\WINNT\security\templates\policies\gpt00000.dom SUCCESS       &lt;br /&gt;13:34:44.6379161 alg.exe 3384 CloseFile C:\WINNT\security\templates\policies\gpt00001.inf SUCCESS       &lt;br /&gt;13:34:44.6381773 alg.exe 3384 CloseFile C:\WINNT\security\templates\policies\gpt00002.inf SUCCESS&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;Ho preso il &lt;b&gt;call stack&lt;/b&gt; da &lt;b&gt;process monitor&lt;/b&gt; per la &lt;b&gt;createfile&lt;/b&gt; del processo &lt;b&gt;ALG.exe&lt;/b&gt; sul file &lt;b&gt;TMPGPTFL.INF &lt;/b&gt;. Qui sotto il &lt;b&gt;call stack&lt;/b&gt; preso da &lt;b&gt;process monitor:&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;&lt;/i&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font size="2"&gt;&lt;font face="Courier New"&gt;13:34:40.5168152 alg.exe 3384 CreateFile C:\ SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened          &lt;br /&gt;&lt;/font&gt;&lt;/font&gt;-----------------------------------------------------------------------------------------------------       &lt;br /&gt;&lt;font size="2"&gt;&lt;font face="Courier New"&gt;0&amp;#160; fltMgr.sys&amp;#160;&amp;#160; fltMgr.sys + 0x1944&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0xf84b1944 C:\WINNT\System32\Drivers\fltMgr.sys          &lt;br /&gt;1&amp;#160; fltMgr.sys&amp;#160;&amp;#160; fltMgr.sys + 0x3352&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0xf84b3352 C:\WINNT\System32\Drivers\fltMgr.sys           &lt;br /&gt;2&amp;#160; fltMgr.sys&amp;#160;&amp;#160; fltMgr.sys + 0xfccb&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0xf84bfccb C:\WINNT\System32\Drivers\fltMgr.sys           &lt;br /&gt;3&amp;#160; fltMgr.sys&amp;#160;&amp;#160; &lt;/font&gt;&lt;/font&gt;&lt;font size="2"&gt;&lt;font face="Courier New"&gt;fltMgr.sys + 0x10142&amp;#160;&amp;#160;&amp;#160; 0xf84c0142 C:\WINNT\System32\Drivers\fltMgr.sys          &lt;br /&gt;4&amp;#160; ntkrnlpa.exe ntkrnlpa.exe + 0x17003&amp;#160; 0x804ee003 C:\WINNT\system32\ntkrnlpa.exe           &lt;br /&gt;5&amp;#160; ntkrnlpa.exe ntkrnlpa.exe + 0x17003&amp;#160; 0x804ee003 C:\WINNT\system32\ntkrnlpa.exe           &lt;br /&gt;6&amp;#160; ntkrnlpa.exe ntkrnlpa.exe + 0xdc996&amp;#160; 0x805b3996 C:\WINNT\system32\ntkrnlpa.exe           &lt;br /&gt;7&amp;#160; ntkrnlpa.exe ntkrnlpa.exe + 0xd8e77&amp;#160; 0x805afe77 C:\WINNT\system32\ntkrnlpa.exe           &lt;br /&gt;8&amp;#160; ntkrnlpa.exe ntkrnlpa.exe + 0x93431&amp;#160; 0x8056a431 C:\WINNT\system32\ntkrnlpa.exe           &lt;br /&gt;9&amp;#160; ntkrnlpa.exe ntkrnlpa.exe + 0x93da8&amp;#160; 0x8056ada8 C:\WINNT\system32\ntkrnlpa.exe           &lt;br /&gt;10 ntkrnlpa.exe ntkrnlpa.exe + 0x9647a&amp;#160; 0x8056d47a C:\WINNT\system32\ntkrnlpa.exe           &lt;br /&gt;11 ntkrnlpa.exe ntkrnlpa.exe + 0x65a48&amp;#160; 0x8053ca48 C:\WINNT\system32\ntkrnlpa.exe           &lt;br /&gt;12 ntkrnlpa.exe ntkrnlpa.exe + 0x26755&amp;#160; 0x804fd755 C:\WINNT\system32\ntkrnlpa.exe           &lt;br /&gt;13 ntkrnlpa.exe ntkrnlpa.exe + 0x13e1cc 0x806151cc C:\WINNT\system32\ntkrnlpa.exe           &lt;br /&gt;14 ntkrnlpa.exe ntkrnlpa.exe + 0x13eb9d 0x80615b9d C:\WINNT\system32\ntkrnlpa.exe           &lt;br /&gt;15 ntkrnlpa.exe ntkrnlpa.exe + 0x13efd4 0x80615fd4 C:\WINNT\system32\ntkrnlpa.exe           &lt;br /&gt;16 ntkrnlpa.exe ntkrnlpa.exe + 0xedca7&amp;#160; 0x805c4ca7 C:\WINNT\system32\ntkrnlpa.exe           &lt;br /&gt;17 ntkrnlpa.exe ntkrnlpa.exe + 0x6a1e2&amp;#160; 0x805411e2 C:\WINNT\system32\ntkrnlpa.exe&lt;i&gt;&lt;/i&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;i&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Process Monitor&lt;/strong&gt;, non avendo configurato i simboli, non mostra il &lt;strong&gt;call stack decodificato&lt;/strong&gt;, procedendo alla decodifica degli indirizzi che vediamo sul call stack,tramite i simboli di debugging, ho ottenuto quanto segue:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font size="2" face="Courier New"&gt;1:34:41.2317561 PM alg.exe 3384&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; CreateFile&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; C:\WINNT\security\templates\policies&amp;#160;&amp;#160; SUCCESS&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened        &lt;br /&gt;-----------------------------------------------------------------------------------------------------         &lt;br /&gt;0&amp;#160; fltMgr.sys&amp;#160;&amp;#160; fltMgr!FltpPerformPreCallbacks+0x2d4 0xf84b1944 C:\WINNT\System32\Drivers\fltMgr.sys         &lt;br /&gt;1&amp;#160; fltMgr.sys&amp;#160;&amp;#160; fltMgr!FltpPassThroughInternal+0x32&amp;#160; 0xf84b3352 C:\WINNT\System32\Drivers\fltMgr.sys         &lt;br /&gt;2&amp;#160; fltMgr.sys&amp;#160;&amp;#160; fltMgr!FltpPassThrough+0x1df&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0xf84b3c15 C:\WINNT\System32\Drivers\fltMgr.sys         &lt;br /&gt;3&amp;#160; fltMgr.sys&amp;#160;&amp;#160; fltMgr!FltpDispatch+0xf3&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0xf84b3ffb C:\WINNT\System32\Drivers\fltMgr.sys         &lt;br /&gt;4&amp;#160; ntkrnlpa.exe nt!IopfCallDriver+0x31&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0x804ee003 C:\WINNT\system32\ntkrnlpa.exe         &lt;br /&gt;5&amp;#160; ntkrnlpa.exe nt!IopfCallDriver+0x31&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0x804ee003 C:\WINNT\system32\ntkrnlpa.exe         &lt;br /&gt;6&amp;#160; ntkrnlpa.exe nt!NtQueryDirectoryFile+0x5d&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0x8056e29f C:\WINNT\system32\ntkrnlpa.exe         &lt;br /&gt;7&amp;#160; ntkrnlpa.exe nt!KiFastCallEntry+0xf8&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0x8053ca48 C:\WINNT\system32\ntkrnlpa.exe         &lt;br /&gt;8&amp;#160; ntkrnlpa.exe nt!ZwQueryDirectoryObject&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0x804fdfc5 C:\WINNT\system32\ntkrnlpa.exe         &lt;br /&gt;9&amp;#160; ntkrnlpa.exe nt!CcPfPrefetchMetadata+0x76&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0x806151cc C:\WINNT\system32\ntkrnlpa.exe         &lt;br /&gt;10 ntkrnlpa.exe nt!CcPfPrefetchScenario+0x6d&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0x80615b9d C:\WINNT\system32\ntkrnlpa.exe         &lt;br /&gt;11 ntkrnlpa.exe nt!CcPfBeginAppLaunch+0x158&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0x80615fd4 C:\WINNT\system32\ntkrnlpa.exe         &lt;br /&gt;12 ntkrnlpa.exe nt!PspUserThreadStartup+0xeb&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0x805c4ca7 C:\WINNT\system32\ntkrnlpa.exe         &lt;br /&gt;13 ntkrnlpa.exe nt!KiThreadStartup+0x16&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0x805411e2 C:\WINNT\system32\ntkrnlpa.exe&lt;/font&gt; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;i&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;Analizzando le funzioni riportare sopra si identifica che il sistema di &lt;b&gt;prefetching&lt;/b&gt; ha generato la scansione dei file e delle cartelle. Quando il processo &lt;b&gt;ALG&lt;/b&gt; parte e crea il primo &lt;b&gt;thread&lt;/b&gt; è eseguito in &lt;b&gt;kernel mode&lt;/b&gt; il codice che esegue il &lt;b&gt;prefetching.&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Riporto il log che mostra questa sequenza:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font size="2" face="Courier New"&gt;13:34:40.1881511 alg.exe 3384 Process Start SUCCESS Parent PID: 1100        &lt;br /&gt;13:34:40.1966276 alg.exe 3384 Load Image C:\WINNT\system32\alg.exe SUCCESS Image Base: 0x1000000, Image Size: 0xd000         &lt;br /&gt;13:34:40.1967013 alg.exe 3384 Load Image C:\WINNT\System32\ntdll.dll SUCCESS Image Base: 0x7c910000, Image Size: 0xb6000         &lt;br /&gt;&lt;/font&gt;&lt;font size="2"&gt;&lt;font face="Courier New"&gt;&lt;font color="#ff0000"&gt;13:34:40.2724867 alg.exe 3384 CreateFile C:\WINNT\Prefetch\ALG.EXE-231187DC.pf SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened            &lt;br /&gt;13:34:40.2725487 alg.exe 3384 QueryStandardInformationFile C:\WINNT\Prefetch\ALG.EXE-231187DC.pf SUCCESS AllocationSize: 54,784, EndOfFile: 54,568, NumberOfLinks: 1, DeletePending: False, Directory: False             &lt;br /&gt;13:34:40.2725791 alg.exe 3384 ReadFile C:\WINNT\Prefetch\ALG.EXE-231187DC.pf SUCCESS Offset: 0, Length: 54,568             &lt;br /&gt;13:34:40.2728658 alg.exe 3384 CloseFile C:\WINNT\Prefetch\ALG.EXE-231187DC.pf SUCCESS             &lt;br /&gt;&lt;/font&gt;13:34:40.5168152 alg.exe 3384 CreateFile C:\ SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened&lt;i&gt;&lt;/i&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;i&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;Come potete vedere nel log il processo &lt;b&gt;ALG.exe &lt;/b&gt;legge il file &lt;b&gt;alg.exe.&amp;lt;hashcode&amp;gt;.pf&lt;/b&gt; per determinare quali cartelle e file caricarsi in memoria durante il &lt;b&gt;prefetching&lt;/b&gt;.&amp;#160; In questo caso specifico ho riscontrato una dimensione notevole del file &lt;b&gt;alg.exe.&amp;lt;hashcode&amp;gt;.pf (54K) &lt;/b&gt;che&lt;b&gt; &lt;/b&gt;rivela come il file contenga notevoli cartelle e file da caricare e sicuramente anche il path &lt;b&gt;C:\WINNT\SECURITY\TEMPLATES\POLICIES. &lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Per comprendere come mai il file &lt;b&gt;alg.exe.&amp;lt;hashcode&amp;gt;.pf &lt;/b&gt;contenga cosi tante cartelle e file ho effettuato un test notando che eseguendo un processo qualsiasi, nel nostro caso la calcolatrice, durante la scansione dell’Antivirus, il file &lt;b&gt;Calc.exe.&amp;lt;hashcode&amp;gt;.pg &lt;/b&gt;generato è di 60k mentre normalmente è di 10-15k.&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;h3&gt;Causa&lt;/h3&gt;  &lt;p&gt;Durante l’aggiornamento del file &lt;b&gt;alg.exe.&amp;lt;hashcode&amp;gt;.pf&lt;/b&gt;, l’antivirus o qualsiasi altra applicazione esegue la scansione del sistema accedendo tutti i file e generando un file *.&lt;b&gt;pf &lt;/b&gt;di grosse dimensione. Quando il servizio &lt;b&gt;ALG.exe&lt;/b&gt; è avviato leggerà, durante il&lt;b&gt; prefetching, &lt;/b&gt;il file &lt;b&gt;alg.exe.&amp;lt;hashcode&amp;gt;.pf&amp;#160; &lt;/b&gt;che contiene tutti i file e cartelle di sistema e anche il file &lt;b&gt;C:\WINNT\security\templates\policies\tmpgptfl.inf&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;h3&gt;Soluzione&lt;/h3&gt;  &lt;p&gt;Individuare il software che fa la scansione di tutti i file anche se molto probabilmente si tratta dell’&lt;b&gt;Antivirus&lt;/b&gt;. Configurare questa applicazione per non accedere ai file sotto &lt;strong&gt;C:\WINNT\SECURITY\TEMPLATES\POLICIES.&lt;/strong&gt; Nel nostro caso troviamo prima dell’evento 1001 un evento generato dal processo &lt;strong&gt;ntrtscan.exe (Trend Micro OfficeScan Real-time Scan Service) &lt;/strong&gt;che conferma che la causa è l’antivirus.&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;&lt;u&gt;&lt;/u&gt;&lt;/i&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Description:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Trend Micro OfficeScan Real-time Scan Service (32-bit)      &lt;br /&gt;Company:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Trend Micro Inc.       &lt;br /&gt;Name:&amp;#160;&amp;#160; ntrtscan.exe       &lt;br /&gt;Version: 8.00.0000.1189       &lt;br /&gt;Path:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; C:\Programmi\Trend Micro\OfficeScan Client\ntrtscan.exe       &lt;br /&gt;Command Line:&amp;#160; &amp;quot;C:\Programmi\Trend Micro\OfficeScan Client\ntrtscan.exe&amp;quot;       &lt;br /&gt;PID:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 800       &lt;br /&gt;Parent PID:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 1100       &lt;br /&gt;Session ID:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0       &lt;br /&gt;User:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; NT AUTHORITY\SYSTEM       &lt;br /&gt;Auth ID:&amp;#160; 00000000:000003e7       &lt;br /&gt;Architecture:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 32-bit       &lt;br /&gt;Virtualized:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; n/a       &lt;br /&gt;Integrity: n/a       &lt;br /&gt;Started:&amp;#160; 12/16/2008 1:33:57 PM       &lt;br /&gt;Ended:&amp;#160;&amp;#160; (Running)       &lt;br /&gt;Modules:       &lt;br /&gt;NTRtScan.exe&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0x400000&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0xd8000&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; C:\Programmi\Trend Micro\OfficeScan Client\NTRtScan.exe       &lt;br /&gt;Date &amp;amp; Time:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 12/16/2008 1:34:42 PM       &lt;br /&gt;Event Class:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Registry       &lt;br /&gt;Operation:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; RegSetValue       &lt;br /&gt;Result:&amp;#160; SUCCESS       &lt;br /&gt;Path:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; HKLM\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.\LastScannedFileName       &lt;br /&gt;TID:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 868       &lt;br /&gt;Duration:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0.0000277       &lt;br /&gt;Type:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; REG_SZ       &lt;br /&gt;Length:&amp;#160; 101       &lt;br /&gt;Data:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; C:\WINNT\SECURITY\TEMPLATES\POLICIES\TMPGPTFL.INF&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;L’evento sopra mostra che l’antivirus verifica i file &lt;b&gt;TMPGPTFL.INF&lt;/b&gt; infatti il servizio ha impostato la chiave &lt;b&gt;LastScannedFileName &lt;/b&gt;con il valore &lt;b&gt;C:\WINNT\SECURITY\TEMPLATES\POLICIES\TMPGPTFL.INF.&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;Per verificare velocemente se siete in questa condizione potete provare a disabilitare il &lt;b&gt;prefetching &lt;/b&gt;in modo da evitare il comportamento descritto sopra.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Key: &lt;b&gt;HKEY_LOCAL_MACHINE\SYST&lt;/b&gt;&lt;b&gt;EM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters&lt;/b&gt;       &lt;br /&gt;Name: &lt;b&gt;EnablePrefetcher&lt;/b&gt;       &lt;br /&gt;Type: &lt;b&gt;REG_DWORD&lt;/b&gt;       &lt;br /&gt;Value: &lt;b&gt;0&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;The &lt;b&gt;EnablePrefetcher&lt;/b&gt; key has the following values:&lt;/p&gt;    &lt;p&gt;0 = Disabled      &lt;br /&gt;1 = Application launch prefetching enabled       &lt;br /&gt;2 = Boot prefetching enabled       &lt;br /&gt;3 = Application launch and boot enabled &lt;/p&gt;    &lt;p&gt;To disable Prefetch, set the value to 0.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Se il problema si risolve con il &lt;b&gt;prefetching&lt;/b&gt; disabilitato avete una conferma alla analisi.&lt;/p&gt;  &lt;p&gt;In caso affermativo dovrete lavorare con il supporto dell&lt;b&gt;’Applicativo&lt;/b&gt; per configurare e applicare l’exclusion dell’antivirus per la cartella &lt;strong&gt;C:\WINNT\SECURITY\TEMPLATES\POLICIES&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/itasupport/pages/matteo-belloni.aspx"&gt;Matteo Belloni&lt;/a&gt;     &lt;br /&gt;Support Escalation Engineer     &lt;br /&gt;Microsoft Enterprise Platform Support&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3229159" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/itasupport/archive/tags/Windows+Team/default.aspx">Windows Team</category><category domain="http://blogs.technet.com/itasupport/archive/tags/Matteo+Belloni/default.aspx">Matteo Belloni</category><category domain="http://blogs.technet.com/itasupport/archive/tags/Directory+Services/default.aspx">Directory Services</category><category domain="http://blogs.technet.com/itasupport/archive/tags/Group+Policy/default.aspx">Group Policy</category><category domain="http://blogs.technet.com/itasupport/archive/tags/Restricted+Group/default.aspx">Restricted Group</category></item><item><title>Restricted Group – Funzionalità e Applicazione</title><link>http://blogs.technet.com/itasupport/archive/2009/04/13/restricted-group-funzionalit-e-applicazione.aspx</link><pubDate>Mon, 13 Apr 2009 02:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3223883</guid><dc:creator>itentblg</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/itasupport/comments/3223883.aspx</comments><wfw:commentRss>http://blogs.technet.com/itasupport/commentrss.aspx?PostID=3223883</wfw:commentRss><description>&lt;p&gt;I &lt;strong&gt;Restricted Group&lt;/strong&gt; permettono agli amministratori di definire e gestire i gruppi locali su server e computer del dominio.     &lt;br /&gt;L’esempio classico è l’introduzione di un gruppo di amministratori nel gruppo &lt;strong&gt;Administrators&lt;/strong&gt; locale.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image15.png"&gt;&lt;img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image15_thumb.png" width="536" height="521" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Il processo per l’applicazione dei Restricted Group ai vari computer avviene tramite l’applicazione delle Group Policy:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Il client richiede al Domain Controller la lista delle Group Policy da applicare al computer. &lt;/li&gt;    &lt;li&gt;Il Domain Controller risponde con la lista delle Group Policy da applicare. &lt;/li&gt;    &lt;li&gt;La lista è processata e, per ogni policy nella SYSVOL, è copiato il file &lt;strong&gt;GptTmpl.inf&lt;/strong&gt; nel file &lt;strong&gt;tmpgptfl.inf&lt;/strong&gt; locale nella cartella &lt;strong&gt;C:\Windows\Security\Templates\Policies&lt;/strong&gt;.&lt;a href="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image5.png"&gt;        &lt;br /&gt;        &lt;p&gt;&lt;/p&gt;     &lt;/a&gt;&lt;a href="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image5.png"&gt;&lt;img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image5_thumb.png" width="969" height="159" /&gt;&lt;/a&gt;&lt;/a&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;Dopo la copia, il file &lt;strong&gt;tmpgptfl.inf&lt;/strong&gt; è aperto e modificato inserendo due righe (&lt;strong&gt;GPOPath… &lt;/strong&gt;e&lt;strong&gt; DSPath…&lt;/strong&gt;) che riportano l’informazione della policy da dove è stato copiato il file e successivamente è salvato nel formato &lt;strong&gt;gpt0000X.dom/inf&lt;/strong&gt;&lt;/p&gt;      &lt;p&gt;&lt;strong&gt;&lt;a href="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image10.png"&gt;&lt;img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image10_thumb.png" width="977" height="205" /&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;Per ogni file &lt;strong&gt;GptTmpl.inf&lt;/strong&gt; nelle Group Policy troviamo un file in locale: &lt;strong&gt;gpt00000.dom, gpt00001.dom, gpt0000X2inf&lt;/strong&gt;.       &lt;br /&gt;Un esempio della cartella &lt;strong&gt;C:\Windows\Security\Templates\Policies&lt;/strong&gt;&lt;a href="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image_12.png"&gt;        &lt;br /&gt;        &lt;p&gt;&lt;/p&gt;     &lt;/a&gt;&lt;a href="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image_12.png"&gt;&lt;img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image_thumb.png" width="699" height="117" /&gt;&lt;/a&gt;&lt;/a&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Successivamente i file sono letti e le policy applicate. Per quanto riguarda i &lt;strong&gt;Restricted Group&lt;/strong&gt; è letta la configurazione sotto &lt;strong&gt;[Group Membership]&lt;/strong&gt;.       &lt;br /&gt;Prendendo l’esempio sopra troviamo giustamente i due &lt;strong&gt;SID &lt;/strong&gt;del gruppo &lt;strong&gt;GruppoAmmComputer&lt;/strong&gt; e dell’utente &lt;strong&gt;Mbelloni&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;Per controllare che la policy sia applicata correttamente si può analizzare il &lt;strong&gt;winlogon.log&lt;/strong&gt; sotto &lt;strong&gt;C:\Windows\Security\Logs&lt;/strong&gt;.       &lt;br /&gt;Nel nostro esempio sono stati rimossi i gruppi e utenti presenti ed è stato aggiunto l’utente &lt;strong&gt;Mbelloni        &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image31.png"&gt;&lt;img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image31_thumb.png" width="702" height="289" /&gt;&lt;/a&gt;&lt;/p&gt;     &lt;/strong&gt;&lt;/li&gt;    &lt;li&gt;Successivamente è stata modificata la &lt;strong&gt;Group Policy&lt;/strong&gt; aggiungendo il gruppo “&lt;strong&gt;GruppoAmmComputer&lt;/strong&gt;” nei &lt;strong&gt;Restricted Group        &lt;br /&gt;        &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;a href="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image_26.png"&gt;&lt;img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image_thumb_11.png" width="673" height="500" /&gt;&lt;/a&gt;&lt;/p&gt;     &lt;/strong&gt;      &lt;p align="left"&gt;Questo è il log successivo all’applicazione delle GPO dopo la modifica:&lt;/p&gt;      &lt;p&gt;&lt;img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image_thumb_8.png" width="559" height="203" /&gt; &lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;L’evento &lt;strong&gt;SceCli 1704&lt;/strong&gt; segnala che la policy è stata applicata con successo senza errori.&lt;/p&gt;      &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image_24.png"&gt;&lt;img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/itasupport/WindowsLiveWriter/ProblemiconlapplicazionedelleRestricted_A97B/image_thumb_10.png" width="402" height="450" /&gt;&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;Maggiori informazioni sono disponibili nel seguente articolo:    &lt;br /&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/ms814788.aspx" target="_blank"&gt;MSDN - Restricted Groups&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/itasupport/pages/matteo-belloni.aspx"&gt;Matteo Belloni&lt;/a&gt;     &lt;br /&gt;Support Escalation Engineer     &lt;br /&gt;Microsoft Enterprise Platform Support&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3223883" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/itasupport/archive/tags/Windows+Team/default.aspx">Windows Team</category><category domain="http://blogs.technet.com/itasupport/archive/tags/Matteo+Belloni/default.aspx">Matteo Belloni</category><category domain="http://blogs.technet.com/itasupport/archive/tags/Directory+Services/default.aspx">Directory Services</category><category domain="http://blogs.technet.com/itasupport/archive/tags/Group+Policy/default.aspx">Group Policy</category><category domain="http://blogs.technet.com/itasupport/archive/tags/Restricted+Group/default.aspx">Restricted Group</category></item></channel></rss>