We have workstations here that did not include Domain Users in the local Administrators group. Now we went and globally added the group. But we are finding hundreds of machines still that when they logon @PRIV = "USER" instead of "ADMIN". Even when we add that group manually and watch a user logon, @PRIV still does not equal "ADMIN". Even stranger, now that this @PRIV check was added to the logon scripts, we've found that sometimes some of the Domain Admins get @PRIV = "USER". I was wondering if anyone else has had this problem, and what did you do to fix it?