AppendixA.Deployingpowerschemesfornon-administrator
groupsorusersonWindowsXPclientcomputers
Non-administratorgroupsorusersonWindowsXPclientcomputershavenopermissiontochangethe
powerschemesettings.Bydesign,thisisafeatureoftheWindowsXPoperatingsystem.TodeployPower
ManagerplanssuccessfullytoWindowsXPclientcomputersfornon-administratorgroupsorusers,theIT
administratorneedstocongurethedomainserverbydoingthefollowing:
1.Onadomainserver,clickStart➙Run,andtypedsa.mscintheOpenbox.TheActiveDirectoryUsers
andComputerswindowopens.
2.Right-clickonadomaincontainerandselectProperties.ThePropertieswindowopens.
3.ClicktheGroupPolicytab,andclicktheNewbuttontocreateanewgrouppolicyobject.
4.RenamethegrouppolicyobjectwithPowerCongurationPolicyandpressEnter.
5.ClickEdit.TheGroupPolicyObjectEditoropens.
6.Setthesecuritypermissionforthefollowingkey:
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ControlsFolder\PowerCfg
bydoingthefollowing:
a.UnderComputerConguration,clickWindowsSettings➙SecuritySettings,right-clickRegistry,
andselectAddKey.TheSelectRegistryKeywindowopens.
b.TypethefollowingkeyintheSelectedkeybox:
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ControlsFolder\PowerCfg
c.ClickOK.TheDatabaseSecuritywindowopens.
d.OntheSecuritytab,selectthenon-administratorgroup(s)oruser(s)youwanttogivepermissionto,
assignFullControlpermissiontothegroup(s)oruser(s),andclickApply.
e.ClickAdvanced.Theadvancedwindowopens.
f.OnthePermissionstab,selectthegroup(s)oruser(s),selecttheAllowinheritablepermissions
fromtheparenttopropagatetothisobjectandallchildobjects.Includethesewithentries
explicitlydenedhere."option,andclickOK.TheAddObjectwindowopens.
g.SelectthePropagateinheritablepermissionstoallsubkeysoption,andclickOK.
7.Setthesecuritypermissionforthefollowingkey:
USERS\.DEFAULT\ControlPanel\PowerCfg
bydoingthefollowing:
a.UnderComputerConguration,clickWindowsSettings➙SecuritySettings,right-clickRegistry,
andselectAddKey.TheSelectRegistryKeywindowopens.
b.TypethefollowingkeyintheSelectedkeybox:
USERS\.DEFAULT\ControlPanel\PowerCfg
c.ClickOK.TheDatabaseSecuritywindowopens.
d.OntheSecuritytab,selectthenon-administratorgroup(s)oruser(s)youwanttogivepermissionto,
assignFullControlpermissiontothegroup(s)oruser(s),andclickApply.
e.ClickAdvanced.Theadvancedwindowopens.
f.OnthePermissionstab,selectthegroup(s)oruser(s),selecttheAllowinheritablepermissions
fromtheparenttopropagatetothisobjectandallchildobjects.Includethesewithentries
explicitlydenedhere."option,andclickOK.TheAddObjectwindowopens.
g.SelectthePropagateinheritablepermissionstoallsubkeysoption,andclickOK.
8.ChecktherearetwogrouppolicyobjectsgeneratedintheActiveDirectoryUsersandComputers
window:
©CopyrightLenovo2008,2011
45