Customer has C:\ drive restricted by Group Policy.
Most things work fine but for some reason when users try to save emails to their default location (H:\ drive = users home drive) by using "File | Save As" the SECOND time they try it (it works the first time), it fails with the error message:
"Restrictions: This operation has been cancelled due to restrictions on in effect on this computer. Please contact your system administrator"
If the GPO is changed to remove the restirction on the C:\ drive then the operation works fine, every time an email is saved so it must be the C:\ drive restriction that is causing the issue.
The following registry keys have been set which should mitigate the restriction placed on C:\:
HKEY_CURRENT HKEY_CURRENT USER\Software\Microsoft\Office\14.0\Outlook\Options\DefaultPath
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\14.0\Outlook\Security\OutlookSecureTempFolder
Further analysis has been conducted using Sysinternals Process Monitor and the relevant results are pasted below:
14:39:25.3508144 OUTLOOK.EXE 3780 CreateFile \\fileserver\UserData\WindowsUser\monday1243.msg SUCCESS Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14:39:25.3512482 OUTLOOK.EXE 3780 CreateFile \\fileserver\UserData\ SUCCESS Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14:39:25.3524734 Explorer.EXE 2912 CreateFile \\fileserver\UserData\WindowsUser\monday1243.msg SUCCESS Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14:39:25.3531862 OUTLOOK.EXE 3780 QueryNetworkPhysicalNameInformationFile \\fileserver\UserData\ SUCCESS
14:39:25.3539522 OUTLOOK.EXE 3780 CloseFile \\fileserver\UserData\ SUCCESS
14:39:25.3539707 OUTLOOK.EXE 3780 QuerySecurityFile \\fileserver\UserData\WindowsUser\monday1243.msg SUCCESS Information: Owner, Group, DACL
14:39:25.3543375 OUTLOOK.EXE 3780 CreateFile \\fileserver\PIPE\srvsvc SUCCESS Desired Access: Generic Read/Write, Disposition: Open, Options: Non-Directory File, Open No Recall, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
14:39:25.3559260 OUTLOOK.EXE 3780 SetPipeInformation \\fileserver\PIPE\srvsvc SUCCESS
14:39:25.3560269 OUTLOOK.EXE 3780 WriteFile \\fileserver\PIPE\srvsvc SUCCESS Offset: 0, Length: 116, Priority: Normal
14:39:25.3566989 OUTLOOK.EXE 3780 ReadFile \\fileserver\PIPE\srvsvc SUCCESS Offset: 0, Length: 92, Priority: Normal
14:39:25.3569918 OUTLOOK.EXE 3780 CloseFile \\fileserver\UserData\WindowsUser\monday1243.msg SUCCESS
14:39:25.3574141 OUTLOOK.EXE 3780 FileSystemControl \\fileserver\PIPE\srvsvc SUCCESS Control: FSCTL_PIPE_TRANSCEIVE, WriteLength: 1,024, ReadLength: 96
14:39:25.3577193 Explorer.EXE 2912 QueryInformationVolume \\fileserver\UserData\WindowsUser\monday1243.msg BUFFER OVERFLOW VolumeCreationTime: 21/06/2005 15:44:19, VolumeSerialNumber: EAB6-26B5, SupportsObjects: True, VolumeLabel: UseĜ
14:39:25.3581728 OUTLOOK.EXE 3780 CloseFile \\fileserver\PIPE\srvsvc SUCCESS
14:39:25.3609033 Explorer.EXE 2912 QueryAllInformationFile \\fileserver\UserData\WindowsUser\monday1243.msg BUFFER OVERFLOW CreationTime: 27/06/2011 14:39:19, LastAccessTime: 27/06/2011 14:39:20, LastWriteTime: 27/06/2011 14:39:24, ChangeTime: 27/06/2011 14:39:20, FileAttributes: A, AllocationSize: 32,768, EndOfFile: 29,184, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x60000000c4ec0, EaSize: 0, Access: None, Position: 0, Mode: , AlignmentRequirement: Byte
14:39:25.3621231 OUTLOOK.EXE 3780 CreateFile \\fileserver\UserData\WindowsUser\37426CE3.tmp ACCESS DENIED Desired Access: Write DAC, Write Owner, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
14:39:25.3628587 OUTLOOK.EXE 3780 CreateFile \\fileserver\UserData\WindowsUser\monday1243.msg SUCCESS Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14:39:25.3658499 Explorer.EXE 2912 FileSystemControl \\fileserver\UserData\WindowsUser\monday1243.msg SUCCESS Control: FSCTL_CREATE_OR_GET_OBJECT_ID
14:39:25.3670646 OUTLOOK.EXE 3780 QueryInformationVolume \\fileserver\UserData\WindowsUser\monday1243.msg BUFFER OVERFLOW VolumeCreationTime: 21/06/2005 15:44:19, VolumeSerialNumber: EAB6-26B5, SupportsObjects: True, VolumeLabel: UseĜ
14:39:25.3674303 OUTLOOK.EXE 3780 CreateFile \\fileserver\UserData\WindowsUser\monday1243.msg PRIVILEGE NOT HELD Desired Access: Generic Read, Delete, Access System Security, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
14:39:25.3698641 OUTLOOK.EXE 3780 QueryAllInformationFile \\fileserver\UserData\WindowsUser\monday1243.msg BUFFER OVERFLOW CreationTime: 27/06/2011 14:39:19, LastAccessTime: 27/06/2011 14:39:20, LastWriteTime: 27/06/2011 14:39:24, ChangeTime: 27/06/2011 14:39:20, FileAttributes: A, AllocationSize: 32,768, EndOfFile: 29,184, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x60000000c4ec0, EaSize: 0, Access: None, Position: 0, Mode: , AlignmentRequirement: Byte
14:39:25.3707410 Explorer.EXE 2912 QueryObjectIdInformationVolume \\fileserver\UserData\WindowsUser\monday1243.msg SUCCESS ObjectId: 12D97F1BB3A0F84AAF7B2DBF1BB3D0D8
14:39:25.3714792 OUTLOOK.EXE 3780 CreateFile \\fileserver\UserData\WindowsUser\monday1243.msg SUCCESS Desired Access: Generic Read, Delete, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14:39:25.3743199 OUTLOOK.EXE 3780 FileSystemControl \\fileserver\UserData\WindowsUser\monday1243.msg SUCCESS Control: FSCTL_CREATE_OR_GET_OBJECT_ID
14:39:25.3752229 Explorer.EXE 2912 CloseFile \\fileserver\UserData\WindowsUser\monday1243.msg SUCCESS
If anyone has any ideas on how we can resolve this issue then I would be extremely grateful if you could get in touch as this is a real show stopper from the customers point of view.
Jonathan Conway | MCITP: Enterprise Administrator • MCP • MCSE 2003 • MCTS • VCP