This is one of those circumstances where, provided I could backup the user data before doing so, I'd strongly consider doing a nuke and pave.
When functionality this fundamental to Windows security and core functions is going wacky, you know that there are other things wrong, too.
You could try the DISM/SFC pair, followed by a repair install if needed, to see if any of those rectify the situation. But if they don't, you're far better off getting this user's machine set up again from scratch.