Tuesday 7 February 2012

Unable to edit netlogon in Windows Server 2008

I needed to make a change to a login script that was stored in the netlogon folder on a Windows Server 2008. However I discovered that I couldn't save any changes when logged on as an administrator accessing the share or even when I followed the correct path to the netlogon folder.

After many failed attempts to resolve this problem, I decided to have a search on Google. I eventually came across this thread on the petri.co.il forums.The solution was amazingly simple yet crazy that it was needed. In order to be able to edit files in netlogon you need to navigate to the correct path for netlogon, go up one level to the 'scripts' folder and modify the permissions for this folder. Make sure that the administrator account has the correct permissions for editing the contents of the folder.

Simple. Yet why Microsoft should feel that by default no one (including the administrator) can modify the contents of this folder is beyond me.

4 comments:

  1. Tried these steps, doesn't work.
    To edit/create a logon script to place in the netlogon share, open notepad as administrator, then create the script, save as and browse to the correct directory. I got this from experts exchange and tested it out and it works. UAS seems to be defeating access so I suspect your instructions would work if I disabled UAC.

    ReplyDelete
  2. just if someone stumbles upon this tread, I have a simple solution. Connect to the \\server-name\netlogon share from another machine as a user with domain admin rights. Then you can add/edit/delete anything you want in there. UAC does not work on shares yet :)

    ReplyDelete
  3. Thanks to others for providing their solutions to this problem. Hopefully if anyone else stumbles across this problem there will be a few things they can try.

    ReplyDelete