I configured an account for dynamical local users with cache modus, so if
the account was created by ZEN on the XP-workstation I can logon locally
(workstation only) with the new account. So if I logon on first time at
edirectory, the account is created ("simple user" not "administrator") on
the maschine and the restricted policy is working; the user can not use the
right mouse-button so he can not see the file-browser and so on. After that
I logon locally with this account some restiction of the policy works, but
not all. E.g. the user can use the right mouse-button.
Do anyone know the problem?

Thanks, Klaus Baringhorst