XP Pro Clients, NT4 domain, group policy question

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Jack Knight (none_at_nospam.net)
Date: 12/22/04


Date: Wed, 22 Dec 2004 11:26:15 GMT

Hi,

I have the following scenario:

XP Pro (SP2) laptops
NT4 Domain.
Roaming Profiles.

I need to lock down individual users on the machine, whilst allowing
administrators to do pretty much anything.

I created a group policy with gpedit for the local machine locking down
all the required items, then prevented read access to that policy to the
administrators group with an explicit DENY acl. Works fine at the local
level, new users get all required lockdowns, admins get everything they
need.

However when the machine joins a domain and a user who has never before
logged on to that machine does so, their roaming profiles appear to
completely overwrite the local machine policy, and also cause other
weird effects like items on the start menu from "All Users"
disappearing, which I cannot find a way to put back.

Is there a way to allow only certain parts of the roaming profile (e.g.
mail server settings, IE proxy info etc.) to be loaded into the local
profile, but prevent my carefully crafted start menu and settings being
blatted?

This happens for both normal users and admins.

There is also the spectre of some users having mandatory profiles.

Any help greatly appreciated.

JK



Relevant Pages

  • XP Client/NT4 Domain/Group Policy Question
    ... NT4 Domain. ... I created a group policy with gpedit for the local machine locking down ... administrators group with an explicit DENY acl. ... logged on to that machine does so, their roaming profiles appear to ...
    (microsoft.public.windowsxp.help_and_support)
  • RE: Reappearing Desktop Items after deletion
    ... On local machine delete all local copies of roaming profiles (except ... Administrator and All users) -, ... Check also that on local machines offline files are not used - offline files ...
    (microsoft.public.windows.server.active_directory)
  • Roaming Profiles Server Question
    ... I'm in the process of planning/implementing a new domain to replace the ... Currently we do not have roaming profiles enabled, ... to get all their data off their local machine, ... then seamlessly join it to the 2003 domain and have all the users ...
    (microsoft.public.windows.server.general)
  • Windows 2003 Roaming Profiles Question
    ... I'm in the process of planning/implementing a new domain to replace the ... Currently we do not have roaming profiles enabled, ... to get all their data off their local machine, ... then seamlessly join it to the 2003 domain and have all the users ...
    (microsoft.public.windows.server.general)
  • Re: Minimum security
    ... I have not used roaming profiles, but generally users have full control or at ... As far as all users being local administrators, that is not a good idea unless ... > I have the domain users group set as local administrators on all of my win ...
    (microsoft.public.win2000.security)