I have the same issue, the only way i have been able to get this to work so far is by turinng off UAC (User Account Control) for the users profile. I would like to find another way so that my tech's do not need to "touch" every profile in order to get this to work.