Re: set path for ts roaming profiles not creating profile

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Gautam Anand (gautam_at_hotpop.com)
Date: 10/03/04

  • Next message: Gautam Anand: "Re: set path for ts roaming profiles not creating profile"
    Date: Mon, 4 Oct 2004 00:15:13 +0530
    
    

    The "access to this resource has been denied" is a pretty clear
    indication that its a permissions issue.
    You might want to look at the perms again for:

    1. Shared Folder NTFS and SHARING permissions
    2. By Default in Windows 2003, shares have a read-only on them.
    3. Check again the NTFS perms on the users_profile_folder.
    4. Also check if you have bypass traverse checking enabled in some of
    the policies which are hitting the computer

    You can use gpresult /v to see the output of all the policies hitting
    the computer

    Search for Bypass traverse checking in this article and what it does.
    http://support.microsoft.com/default.aspx?scid=kb;en-us;823659

    Additionally, create a dummy user, set his Terminal Server profile and
    let the profile folder get created itself ie: when the user logs in.
    This is to avoid any misconfigured NTFS/Share permissions which might
    come up.

    Good luck

    -- 
    Gautam Anand
    e: gautam at hotpop dot com
    --------------------------------- 
    "John Stamos" <vexed55@aol.com> wrote in message 
    news:398501c4a964$3da0f940$a601280a@phx.gbl...
    | When I try and put the unc path to the share logged is as
    | the user it gives me an error message "access to resource
    | has been disallowed" I have given the user full control of
    | his directory and I have also given the everyone full
    | control to the PROFILES share. Here is a copy of the
    | userenv.log
    | USERENV(1b8.984) 12:06:47:366 ProcessGPOs:
    | USERENV(1b8.984) 12:06:47:366 ProcessGPOs:
    | USERENV(1b8.984) 12:06:47:366 ProcessGPOs:  Starting
    | computer Group Policy (Background) processing...
    | USERENV(1b8.984) 12:06:47:366 ProcessGPOs:
    | USERENV(1b8.984) 12:06:47:366 ProcessGPOs:
    | USERENV(1b8.984) 12:06:47:366
    | EnterCriticalPolicySectionEx: Entering with timeout 600000
    | and flags 0x0
    | USERENV(1b8.984) 12:06:47:366
    | EnterCriticalPolicySectionEx: Machine critical section has
    | been claimed.  Handle = 0x7d0
    | USERENV(1b8.984) 12:06:47:366
    | EnterCriticalPolicySectionEx: Leaving successfully.
    | USERENV(1b8.984) 12:06:47:366 ProcessGPOs:  Machine role
    | is 3.
    | USERENV(1b8.984) 12:06:47:366 PingComputer: Adapter speed
    | 10000000 bps
    | USERENV(1b8.984) 12:06:47:366 PingComputer:  First time:  0
    | USERENV(1b8.984) 12:06:47:366 PingComputer:  Fast link.
    | Exiting.
    | USERENV(1b8.984) 12:06:47:366 ProcessGPOs: network name is
    | USERENV(1b8.984) 12:06:47:366 ProcessGPOs:  User name is:
    | CN=C42RS1,OU=Domain Controllers,DC=trustdomain1,DC=corp,
    | Domain name is:  trustdomain1.corp
    | USERENV(1b8.984) 12:06:47:366 ProcessGPOs: Domain
    | controller is:  \\c42rs1.trustdomain1.corp  Domain DN is
    | trustdomain1.corp
    | USERENV(1b8.984) 12:06:47:366 ReadGPExtensions: Rsop entry
    | point not found for dskquota.dll.
    | USERENV(1b8.984) 12:06:47:366 ReadGPExtensions: Rsop entry
    | point not found for gptext.dll.
    | USERENV(1b8.984) 12:06:47:366 ReadGPExtensions: Rsop entry
    | point not found for scecli.dll.
    | USERENV(1b8.984) 12:06:47:366 ReadExtStatus: Reading
    | Previous Status for extension {35378EAC-683F-11D2-A89A-
    | 00C04FBBCFA2}
    | USERENV(1b8.984) 12:06:47:366 ReadStatus: Read Extension's
    | Previous status successfully.
    | USERENV(1b8.984) 12:06:47:366 ReadExtStatus: Reading
    | Previous Status for extension {0ACDD40C-75AC-47ab-BAA0-
    | BF6DE7E7FE63}
    | USERENV(1b8.984) 12:06:47:366 ReadExtStatus: Reading
    | Previous Status for extension {25537BA6-77A8-11D2-9B6C-
    | 0000F8080861}
    | USERENV(1b8.984) 12:06:47:366 ReadExtStatus: Reading
    | Previous Status for extension {3610eda5-77ef-11d2-8dc5-
    | 00c04fa31a66}
    | USERENV(1b8.984) 12:06:47:366 ReadExtStatus: Reading
    | Previous Status for extension {426031c0-0b47-4852-b0ca-
    | ac3d37bfcb39}
    | USERENV(1b8.984) 12:06:47:366 ReadExtStatus: Reading
    | Previous Status for extension {42B5FAAE-6536-11d2-AE5A-
    | 0000F87571E3}
    | USERENV(1b8.984) 12:06:47:381 ReadExtStatus: Reading
    | Previous Status for extension {827D319E-6EAC-11D2-A4EA-
    | 00C04F79F83A}
    | USERENV(1b8.984) 12:06:47:381 ReadStatus: Read Extension's
    | Previous status successfully.
    | USERENV(1b8.984) 12:06:47:381 ReadExtStatus: Reading
    | Previous Status for extension {A2E30F80-D7DE-11d2-BBDE-
    | 00C04F86AE3B}
    | USERENV(1b8.984) 12:06:47:381 ReadExtStatus: Reading
    | Previous Status for extension {B1BE8D72-6EAC-11D2-A4EA-
    | 00C04F79F83A}
    | USERENV(1b8.984) 12:06:47:381 ReadStatus: Read Extension's
    | Previous status successfully.
    | USERENV(1b8.984) 12:06:47:381 ReadExtStatus: Reading
    | Previous Status for extension {c6dc5466-785a-11d2-84d0-
    | 00c04fb169f7}
    | USERENV(1b8.984) 12:06:47:381 ReadExtStatus: Reading
    | Previous Status for extension {e437bc1c-aa7d-11d2-a382-
    | 00c04f991e27}
    | USERENV(1b8.984) 12:06:47:381 ProcessGPOs: Calling
    | GetGPOInfo for normal policy mode
    | USERENV(1b8.984) 12:06:47:381 GetGPOInfo:
    | ********************************
    | USERENV(1b8.984) 12:06:47:381 GetGPOInfo:  Entering...
    | USERENV(1b8.984) 12:06:47:381 GetGPOInfo:  Server
    | connection established.
    | USERENV(1b8.984) 12:06:47:381 GetGPOInfo:  Bound
    | successfully.
    | USERENV(1b8.984) 12:06:47:381 SearchDSObject:  Searching
    | <OU=Domain Controllers,DC=trustdomain1,DC=corp>
    | USERENV(1b8.984) 12:06:47:381 SearchDSObject:  Found GPO
    | (s):  <[LDAP://CN={6AC1786C-016F-11D2-945F-
    | 00C04fB984F9},CN=Policies,CN=System,DC=trustdomain1,DC=corp
    | ;0]>
    | USERENV(1b8.984) 12:06:47:381 ProcessGPO:
    | ==============================
    | USERENV(1b8.984) 12:06:47:381 ProcessGPO:  Deferring
    | search for <LDAP://CN={6AC1786C-016F-11D2-945F-
    | 00C04fB984F9},CN=Policies,CN=System,DC=trustdomain1,DC=corp
    | >
    | USERENV(1b8.984) 12:06:47:381 SearchDSObject:  <OU=Domain
    | Controllers,DC=trustdomain1,DC=corp> has the Block From
    | Above attribute set
    | USERENV(1b8.984) 12:06:47:381 SearchDSObject:  Searching
    | <DC=trustdomain1,DC=corp>
    | USERENV(1b8.984) 12:06:47:381 SearchDSObject:  Found GPO
    | (s):  <[LDAP://CN={31B2F340-016D-11D2-945F-
    | 00C04FB984F9},CN=Policies,CN=System,DC=trustdomain1,DC=corp
    | ;0]>
    | USERENV(1b8.984) 12:06:47:381 ProcessGPO:
    | ==============================
    | USERENV(1b8.984) 12:06:47:381 AddGPO:  GPO (null) will not
    | be added to the list since the Block flag is set and this
    | GPO is not in enforce mode.
    | USERENV(1b8.984) 12:06:47:381 ProcessGPO:  Deferring
    | search for <LDAP://CN={31B2F340-016D-11D2-945F-
    | 00C04FB984F9},CN=Policies,CN=System,DC=trustdomain1,DC=corp
    | >
    | USERENV(1b8.984) 12:06:47:397 SearchDSObject:  Searching
    | <CN=Default-First-Site-
    | Name,CN=Sites,CN=Configuration,DC=trustdomain1,DC=corp>
    | USERENV(1b8.984) 12:06:47:397 SearchDSObject:  No GPO(s)
    | for this object.
    | USERENV(1b8.984) 12:06:47:397 EvaluateDeferredGPOs:
    | Searching for GPOs in
    | cn=policies,cn=system,DC=trustdomain1,DC=corp
    | USERENV(1b8.984) 12:06:47:397 ProcessGPO:
    | ==============================
    | USERENV(1b8.984) 12:06:47:397 ProcessGPO:  Searching <CN=
    | {6AC1786C-016F-11D2-945F-
    | 00C04fB984F9},CN=Policies,CN=System,DC=trustdomain1,DC=corp
    | >
    | USERENV(1b8.984) 12:06:47:397 ProcessGPO:  Machine has
    | access to this GPO.
    | USERENV(1b8.984) 12:06:47:397 ProcessGPO:  GPO passes the
    | filter check.
    | USERENV(1b8.984) 12:06:47:397 ProcessGPO:  Found
    | functionality version of:  2
    | USERENV(1b8.984) 12:06:47:397 ProcessGPO:  Found file
    | system path of:
    | <\\trustdomain1.corp\sysvol\trustdomain1.corp\Policies\{6AC
    | 1786C-016F-11D2-945F-00C04fB984F9}>
    | USERENV(1b8.984) 12:06:47:397 ProcessGPO:  Found common
    | name of:  <{6AC1786C-016F-11D2-945F-00C04fB984F9}>
    | USERENV(1b8.984) 12:06:47:397 ProcessGPO:  Found display
    | name of:  <Default Domain Controllers Policy>
    | USERENV(1b8.984) 12:06:47:397 ProcessGPO:  Found machine
    | version of:  GPC is 9, GPT is 9
    | USERENV(1b8.984) 12:06:47:397 ProcessGPO:  Found flags
    | of:  0
    | USERENV(1b8.984) 12:06:47:397 ProcessGPO:  Found
    | extensions:  [{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
    | {803E14A0-B4FB-11D0-A0D0-00A0C90F574B}]
    | USERENV(1b8.984) 12:06:47:397 ProcessGPO:
    | ==============================
    | USERENV(1b8.984) 12:06:47:397 GetGPOInfo:  GPO Local Group
    | Policy doesn't contain any data since the version number
    | is 0.  It will be skipped.
    | USERENV(1b8.984) 12:06:47:397 GetGPOInfo:  Leaving with 1
    | USERENV(1b8.984) 12:06:47:397 GetGPOInfo:
    | ********************************
    | USERENV(1b8.984) 12:06:47:397 ProcessGPOs: Logging Data
    | for Target <C42RS1>.
    | USERENV(1b8.984) 12:06:47:397 ProcessGPOs: OpenThreadToken
    | failed with error 1008, assuming thread is not
    | impersonating
    | USERENV(1b8.984) 12:06:47:397 ProcessGPOs: ----------------
    | -------
    | USERENV(1b8.984) 12:06:47:397 ProcessGPOs: Processing
    | extension Registry
    | USERENV(1b8.984) 12:06:47:397 ReadStatus: Read Extension's
    | Previous status successfully.
    | USERENV(1b8.984) 12:06:47:397 CompareGPOLists:  The lists
    | are the same.
    | USERENV(1b8.984) 12:06:47:397 CheckGPOs: No GPO changes
    | and no security group membership change and extension
    | Registry has NoGPOChanges set.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
    | -------
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
    | -------
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
    | extension Wireless Group Policy
    | USERENV(1b8.984) 12:06:47:413 CompareGPOLists:  The lists
    | are the same.
    | USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
    | but couldn't read extension Wireless Group Policy's status
    | or policy time.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension
    | Wireless Group Policy skipped because both deleted and
    | changed GPO lists are empty.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
    | -------
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
    | extension Folder Redirection
    | USERENV(1b8.984) 12:06:47:413 CompareGPOLists:  The lists
    | are the same.
    | USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
    | but couldn't read extension Folder Redirection's status or
    | policy time.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension
    | Folder Redirection skipped with flags 0x10007.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
    | -------
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
    | extension Microsoft Disk Quota
    | USERENV(1b8.984) 12:06:47:413 CompareGPOLists:  The lists
    | are the same.
    | USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
    | but couldn't read extension Microsoft Disk Quota's status
    | or policy time.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension
    | Microsoft Disk Quota skipped with flags 0x10007.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
    | -------
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
    | extension QoS Packet Scheduler
    | USERENV(1b8.984) 12:06:47:413 CompareGPOLists:  The lists
    | are the same.
    | USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
    | but couldn't read extension QoS Packet Scheduler's status
    | or policy time.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension QoS
    | Packet Scheduler skipped because both deleted and changed
    | GPO lists are empty.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
    | -------
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
    | extension Scripts
    | USERENV(1b8.984) 12:06:47:413 CompareGPOLists:  The lists
    | are the same.
    | USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
    | but couldn't read extension Scripts's status or policy
    | time.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension
    | Scripts skipped because both deleted and changed GPO lists
    | are empty.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
    | -------
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
    | extension Security
    | USERENV(1b8.984) 12:06:47:413 ReadStatus: Read Extension's
    | Previous status successfully.
    | USERENV(1b8.984) 12:06:47:413 CompareGPOLists:  The lists
    | are the same.
    | USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
    | and no security group membership change and extension
    | Security has NoGPOChanges set.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
    | -------
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
    | -------
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
    | extension Internet Explorer Branding
    | USERENV(1b8.984) 12:06:47:413 CompareGPOLists:  The lists
    | are the same.
    | USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
    | but couldn't read extension Internet Explorer Branding's
    | status or policy time.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension
    | Internet Explorer Branding skipped with flags 0x10007.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
    | -------
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
    | extension EFS recovery
    | USERENV(1b8.984) 12:06:47:413 ReadStatus: Read Extension's
    | Previous status successfully.
    | USERENV(1b8.984) 12:06:47:413 CompareGPOLists:  The lists
    | are the same.
    | USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
    | and no security group membership change and extension EFS
    | recovery has NoGPOChanges set.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
    | -------
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
    | -------
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
    | extension Software Installation
    | USERENV(1b8.984) 12:06:47:413 CompareGPOLists:  The lists
    | are the same.
    | USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
    | but couldn't read extension Software Installation's status
    | or policy time.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension
    | Software Installation skipped because both deleted and
    | changed GPO lists are empty.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
    | -------
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
    | extension IP Security
    | USERENV(1b8.984) 12:06:47:413 CompareGPOLists:  The lists
    | are the same.
    | USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
    | but couldn't read extension IP Security's status or policy
    | time.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension IP
    | Security skipped because both deleted and changed GPO
    | lists are empty.
    | USERENV(1b8.984) 12:06:47:413 SetFgRefreshInfo: Next
    | Machine Fg policy Synchronous, Reason: SKU.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: No WMI logging
    | done in this policy cycle.
    | USERENV(1b8.984) 12:06:47:413 LeaveCriticalPolicySection:
    | Critical section 0x7d0 has been released.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Computer Group
    | Policy has been applied.
    | USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Leaving with 1.
    | USERENV(1b8.984) 12:06:47:413
    | EnterCriticalPolicySectionEx: Entering with timeout 600000
    | and flags 0x0
    | USERENV(1b8.984) 12:06:47:413
    | EnterCriticalPolicySectionEx: Machine critical section has
    | been claimed.  Handle = 0x7d0
    | USERENV(1b8.984) 12:06:47:413
    | EnterCriticalPolicySectionEx: Leaving successfully.
    | USERENV(1b8.984) 12:06:47:428 LeaveCriticalPolicySection:
    | Critical section 0x7d0 has been released.
    | USERENV(1b8.984) 12:06:47:428 GPOThread:  Next refresh
    | will happen in 5 minutes
    |
    | >-----Original Message-----
    | >1. Need more details. What happens when the user logs in?
    | Do you get
    | >an error message, an access denied etc
    | >
    | >2. Can you copy paste the profile path you have set here
    | >3. Are the users allowed to login to the Terminal Server
    | with a
    | >default profile? If he can, can the user go to start-run
    | and access
    | >the
    | \\servername\terminalserver_profile_shar_folder\username.
    | >
    | >4. Enable UserEnvironment Logging on the Terminal Server
    | and this
    | >would give you a good answer on whats happening in the
    | background.
    | >Follow this link
    | >
    | >221833 - How to enable user environment debug logging in
    | retail builds
    | >of Windows
    | >http://support.microsoft.com/default.aspx?scid=kb;EN-
    | US;221833
    | >
    | >5. I can have a look at the UserEnv.Log file if you dont
    | find an
    | >answer in that.
    | >
    | >Good luck
    | >
    | >
    | >-- 
    | >Gautam Anand
    | >e: gautam@hotpop.com
    | >-----------------------------------------
    | >
    | >
    | ><anonymous@discussions.microsoft.com> wrote in message
    | >news:2cc701c4a8f9$34f8f330$a401280a@phx.gbl...
    | >| Hi,
    | >|
    | >| I have windows 2003 terminal server configured with a
    | >| group policy and set the option (set path for ts roaming
    | >| profiles) to create profiles on a share, but for some
    | >| reason it's not creating the profile. Any help would be
    | >| greatly appreciated.
    | >|
    | >| John
    | >
    | >
    | >.
    | > 
    

  • Next message: Gautam Anand: "Re: set path for ts roaming profiles not creating profile"

    Relevant Pages

    • Re: set path for ts roaming profiles not creating profile
      ... | USERENV12:06:47:366 ProcessGPOs: ... | Previous Status for extension {35378EAC-683F-11D2-A89A- ... | USERENV12:06:47:381 SearchDSObject: Found GPO ... | USERENV12:06:47:397 CheckGPOs: No GPO changes ...
      (microsoft.public.windows.group_policy)
    • Re: set path for ts roaming profiles not creating profile
      ... USERENV12:06:47:366 ProcessGPOs: ... Previous Status for extension {35378EAC-683F-11D2-A89A- ... USERENV12:06:47:381 SearchDSObject: Found GPO ... USERENV12:06:47:397 CheckGPOs: No GPO changes ...
      (microsoft.public.windows.group_policy)
    • Re: GPO testing
      ... USERENV12:04:02:091 ProcessGPOs: Extension Folder Redirection skipped with flags 0x90007. ... USERENV12:04:02:091 ProcessGPOs: Extension Scripts skipped because both deleted and changed GPO lists are empty. ... USERENV12:04:02:106 CheckGPOs: No GPO changes and no security group membership change and extension Security has NoGPOChanges set. ...
      (microsoft.public.windows.group_policy)
    • Re: set path for ts roaming profiles not creating profile
      ... >| USERENV12:06:47:397 ProcessGPOs: Processing ... >| USERENV12:06:47:397 CheckGPOs: No GPO changes ... >| and no security group membership change and extension ...
      (microsoft.public.windows.group_policy)
    • Re: Event ID 1030 and 1097 every 5 minuttes
      ... controllers policy. ... ProcessGPOs: Starting computer Group Policy processing... ... Reading Previous Status for extension ...
      (microsoft.public.windows.server.active_directory)