Re: set path for ts roaming profiles not creating profile
From: Gautam Anand (gautam_at_hotpop.com)
Date: 10/03/04
- Previous message: Julian Gilbert: "Re: Internet Explorer Maintenance Windows XP SP2"
- In reply to: John Stamos: "Re: set path for ts roaming profiles not creating profile"
- Next in thread: anonymous_at_discussions.microsoft.com: "Re: set path for ts roaming profiles not creating profile"
- Reply: anonymous_at_discussions.microsoft.com: "Re: set path for ts roaming profiles not creating profile"
- Messages sorted by: [ date ] [ thread ]
Date: Mon, 4 Oct 2004 00:15:13 +0530
The "access to this resource has been denied" is a pretty clear
indication that its a permissions issue.
You might want to look at the perms again for:
1. Shared Folder NTFS and SHARING permissions
2. By Default in Windows 2003, shares have a read-only on them.
3. Check again the NTFS perms on the users_profile_folder.
4. Also check if you have bypass traverse checking enabled in some of
the policies which are hitting the computer
You can use gpresult /v to see the output of all the policies hitting
the computer
Search for Bypass traverse checking in this article and what it does.
http://support.microsoft.com/default.aspx?scid=kb;en-us;823659
Additionally, create a dummy user, set his Terminal Server profile and
let the profile folder get created itself ie: when the user logs in.
This is to avoid any misconfigured NTFS/Share permissions which might
come up.
Good luck
--
Gautam Anand
e: gautam at hotpop dot com
---------------------------------
"John Stamos" <vexed55@aol.com> wrote in message
news:398501c4a964$3da0f940$a601280a@phx.gbl...
| When I try and put the unc path to the share logged is as
| the user it gives me an error message "access to resource
| has been disallowed" I have given the user full control of
| his directory and I have also given the everyone full
| control to the PROFILES share. Here is a copy of the
| userenv.log
| USERENV(1b8.984) 12:06:47:366 ProcessGPOs:
| USERENV(1b8.984) 12:06:47:366 ProcessGPOs:
| USERENV(1b8.984) 12:06:47:366 ProcessGPOs: Starting
| computer Group Policy (Background) processing...
| USERENV(1b8.984) 12:06:47:366 ProcessGPOs:
| USERENV(1b8.984) 12:06:47:366 ProcessGPOs:
| USERENV(1b8.984) 12:06:47:366
| EnterCriticalPolicySectionEx: Entering with timeout 600000
| and flags 0x0
| USERENV(1b8.984) 12:06:47:366
| EnterCriticalPolicySectionEx: Machine critical section has
| been claimed. Handle = 0x7d0
| USERENV(1b8.984) 12:06:47:366
| EnterCriticalPolicySectionEx: Leaving successfully.
| USERENV(1b8.984) 12:06:47:366 ProcessGPOs: Machine role
| is 3.
| USERENV(1b8.984) 12:06:47:366 PingComputer: Adapter speed
| 10000000 bps
| USERENV(1b8.984) 12:06:47:366 PingComputer: First time: 0
| USERENV(1b8.984) 12:06:47:366 PingComputer: Fast link.
| Exiting.
| USERENV(1b8.984) 12:06:47:366 ProcessGPOs: network name is
| USERENV(1b8.984) 12:06:47:366 ProcessGPOs: User name is:
| CN=C42RS1,OU=Domain Controllers,DC=trustdomain1,DC=corp,
| Domain name is: trustdomain1.corp
| USERENV(1b8.984) 12:06:47:366 ProcessGPOs: Domain
| controller is: \\c42rs1.trustdomain1.corp Domain DN is
| trustdomain1.corp
| USERENV(1b8.984) 12:06:47:366 ReadGPExtensions: Rsop entry
| point not found for dskquota.dll.
| USERENV(1b8.984) 12:06:47:366 ReadGPExtensions: Rsop entry
| point not found for gptext.dll.
| USERENV(1b8.984) 12:06:47:366 ReadGPExtensions: Rsop entry
| point not found for scecli.dll.
| USERENV(1b8.984) 12:06:47:366 ReadExtStatus: Reading
| Previous Status for extension {35378EAC-683F-11D2-A89A-
| 00C04FBBCFA2}
| USERENV(1b8.984) 12:06:47:366 ReadStatus: Read Extension's
| Previous status successfully.
| USERENV(1b8.984) 12:06:47:366 ReadExtStatus: Reading
| Previous Status for extension {0ACDD40C-75AC-47ab-BAA0-
| BF6DE7E7FE63}
| USERENV(1b8.984) 12:06:47:366 ReadExtStatus: Reading
| Previous Status for extension {25537BA6-77A8-11D2-9B6C-
| 0000F8080861}
| USERENV(1b8.984) 12:06:47:366 ReadExtStatus: Reading
| Previous Status for extension {3610eda5-77ef-11d2-8dc5-
| 00c04fa31a66}
| USERENV(1b8.984) 12:06:47:366 ReadExtStatus: Reading
| Previous Status for extension {426031c0-0b47-4852-b0ca-
| ac3d37bfcb39}
| USERENV(1b8.984) 12:06:47:366 ReadExtStatus: Reading
| Previous Status for extension {42B5FAAE-6536-11d2-AE5A-
| 0000F87571E3}
| USERENV(1b8.984) 12:06:47:381 ReadExtStatus: Reading
| Previous Status for extension {827D319E-6EAC-11D2-A4EA-
| 00C04F79F83A}
| USERENV(1b8.984) 12:06:47:381 ReadStatus: Read Extension's
| Previous status successfully.
| USERENV(1b8.984) 12:06:47:381 ReadExtStatus: Reading
| Previous Status for extension {A2E30F80-D7DE-11d2-BBDE-
| 00C04F86AE3B}
| USERENV(1b8.984) 12:06:47:381 ReadExtStatus: Reading
| Previous Status for extension {B1BE8D72-6EAC-11D2-A4EA-
| 00C04F79F83A}
| USERENV(1b8.984) 12:06:47:381 ReadStatus: Read Extension's
| Previous status successfully.
| USERENV(1b8.984) 12:06:47:381 ReadExtStatus: Reading
| Previous Status for extension {c6dc5466-785a-11d2-84d0-
| 00c04fb169f7}
| USERENV(1b8.984) 12:06:47:381 ReadExtStatus: Reading
| Previous Status for extension {e437bc1c-aa7d-11d2-a382-
| 00c04f991e27}
| USERENV(1b8.984) 12:06:47:381 ProcessGPOs: Calling
| GetGPOInfo for normal policy mode
| USERENV(1b8.984) 12:06:47:381 GetGPOInfo:
| ********************************
| USERENV(1b8.984) 12:06:47:381 GetGPOInfo: Entering...
| USERENV(1b8.984) 12:06:47:381 GetGPOInfo: Server
| connection established.
| USERENV(1b8.984) 12:06:47:381 GetGPOInfo: Bound
| successfully.
| USERENV(1b8.984) 12:06:47:381 SearchDSObject: Searching
| <OU=Domain Controllers,DC=trustdomain1,DC=corp>
| USERENV(1b8.984) 12:06:47:381 SearchDSObject: Found GPO
| (s): <[LDAP://CN={6AC1786C-016F-11D2-945F-
| 00C04fB984F9},CN=Policies,CN=System,DC=trustdomain1,DC=corp
| ;0]>
| USERENV(1b8.984) 12:06:47:381 ProcessGPO:
| ==============================
| USERENV(1b8.984) 12:06:47:381 ProcessGPO: Deferring
| search for <LDAP://CN={6AC1786C-016F-11D2-945F-
| 00C04fB984F9},CN=Policies,CN=System,DC=trustdomain1,DC=corp
| >
| USERENV(1b8.984) 12:06:47:381 SearchDSObject: <OU=Domain
| Controllers,DC=trustdomain1,DC=corp> has the Block From
| Above attribute set
| USERENV(1b8.984) 12:06:47:381 SearchDSObject: Searching
| <DC=trustdomain1,DC=corp>
| USERENV(1b8.984) 12:06:47:381 SearchDSObject: Found GPO
| (s): <[LDAP://CN={31B2F340-016D-11D2-945F-
| 00C04FB984F9},CN=Policies,CN=System,DC=trustdomain1,DC=corp
| ;0]>
| USERENV(1b8.984) 12:06:47:381 ProcessGPO:
| ==============================
| USERENV(1b8.984) 12:06:47:381 AddGPO: GPO (null) will not
| be added to the list since the Block flag is set and this
| GPO is not in enforce mode.
| USERENV(1b8.984) 12:06:47:381 ProcessGPO: Deferring
| search for <LDAP://CN={31B2F340-016D-11D2-945F-
| 00C04FB984F9},CN=Policies,CN=System,DC=trustdomain1,DC=corp
| >
| USERENV(1b8.984) 12:06:47:397 SearchDSObject: Searching
| <CN=Default-First-Site-
| Name,CN=Sites,CN=Configuration,DC=trustdomain1,DC=corp>
| USERENV(1b8.984) 12:06:47:397 SearchDSObject: No GPO(s)
| for this object.
| USERENV(1b8.984) 12:06:47:397 EvaluateDeferredGPOs:
| Searching for GPOs in
| cn=policies,cn=system,DC=trustdomain1,DC=corp
| USERENV(1b8.984) 12:06:47:397 ProcessGPO:
| ==============================
| USERENV(1b8.984) 12:06:47:397 ProcessGPO: Searching <CN=
| {6AC1786C-016F-11D2-945F-
| 00C04fB984F9},CN=Policies,CN=System,DC=trustdomain1,DC=corp
| >
| USERENV(1b8.984) 12:06:47:397 ProcessGPO: Machine has
| access to this GPO.
| USERENV(1b8.984) 12:06:47:397 ProcessGPO: GPO passes the
| filter check.
| USERENV(1b8.984) 12:06:47:397 ProcessGPO: Found
| functionality version of: 2
| USERENV(1b8.984) 12:06:47:397 ProcessGPO: Found file
| system path of:
| <\\trustdomain1.corp\sysvol\trustdomain1.corp\Policies\{6AC
| 1786C-016F-11D2-945F-00C04fB984F9}>
| USERENV(1b8.984) 12:06:47:397 ProcessGPO: Found common
| name of: <{6AC1786C-016F-11D2-945F-00C04fB984F9}>
| USERENV(1b8.984) 12:06:47:397 ProcessGPO: Found display
| name of: <Default Domain Controllers Policy>
| USERENV(1b8.984) 12:06:47:397 ProcessGPO: Found machine
| version of: GPC is 9, GPT is 9
| USERENV(1b8.984) 12:06:47:397 ProcessGPO: Found flags
| of: 0
| USERENV(1b8.984) 12:06:47:397 ProcessGPO: Found
| extensions: [{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
| {803E14A0-B4FB-11D0-A0D0-00A0C90F574B}]
| USERENV(1b8.984) 12:06:47:397 ProcessGPO:
| ==============================
| USERENV(1b8.984) 12:06:47:397 GetGPOInfo: GPO Local Group
| Policy doesn't contain any data since the version number
| is 0. It will be skipped.
| USERENV(1b8.984) 12:06:47:397 GetGPOInfo: Leaving with 1
| USERENV(1b8.984) 12:06:47:397 GetGPOInfo:
| ********************************
| USERENV(1b8.984) 12:06:47:397 ProcessGPOs: Logging Data
| for Target <C42RS1>.
| USERENV(1b8.984) 12:06:47:397 ProcessGPOs: OpenThreadToken
| failed with error 1008, assuming thread is not
| impersonating
| USERENV(1b8.984) 12:06:47:397 ProcessGPOs: ----------------
| -------
| USERENV(1b8.984) 12:06:47:397 ProcessGPOs: Processing
| extension Registry
| USERENV(1b8.984) 12:06:47:397 ReadStatus: Read Extension's
| Previous status successfully.
| USERENV(1b8.984) 12:06:47:397 CompareGPOLists: The lists
| are the same.
| USERENV(1b8.984) 12:06:47:397 CheckGPOs: No GPO changes
| and no security group membership change and extension
| Registry has NoGPOChanges set.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
| -------
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
| -------
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
| extension Wireless Group Policy
| USERENV(1b8.984) 12:06:47:413 CompareGPOLists: The lists
| are the same.
| USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
| but couldn't read extension Wireless Group Policy's status
| or policy time.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension
| Wireless Group Policy skipped because both deleted and
| changed GPO lists are empty.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
| -------
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
| extension Folder Redirection
| USERENV(1b8.984) 12:06:47:413 CompareGPOLists: The lists
| are the same.
| USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
| but couldn't read extension Folder Redirection's status or
| policy time.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension
| Folder Redirection skipped with flags 0x10007.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
| -------
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
| extension Microsoft Disk Quota
| USERENV(1b8.984) 12:06:47:413 CompareGPOLists: The lists
| are the same.
| USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
| but couldn't read extension Microsoft Disk Quota's status
| or policy time.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension
| Microsoft Disk Quota skipped with flags 0x10007.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
| -------
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
| extension QoS Packet Scheduler
| USERENV(1b8.984) 12:06:47:413 CompareGPOLists: The lists
| are the same.
| USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
| but couldn't read extension QoS Packet Scheduler's status
| or policy time.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension QoS
| Packet Scheduler skipped because both deleted and changed
| GPO lists are empty.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
| -------
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
| extension Scripts
| USERENV(1b8.984) 12:06:47:413 CompareGPOLists: The lists
| are the same.
| USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
| but couldn't read extension Scripts's status or policy
| time.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension
| Scripts skipped because both deleted and changed GPO lists
| are empty.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
| -------
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
| extension Security
| USERENV(1b8.984) 12:06:47:413 ReadStatus: Read Extension's
| Previous status successfully.
| USERENV(1b8.984) 12:06:47:413 CompareGPOLists: The lists
| are the same.
| USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
| and no security group membership change and extension
| Security has NoGPOChanges set.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
| -------
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
| -------
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
| extension Internet Explorer Branding
| USERENV(1b8.984) 12:06:47:413 CompareGPOLists: The lists
| are the same.
| USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
| but couldn't read extension Internet Explorer Branding's
| status or policy time.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension
| Internet Explorer Branding skipped with flags 0x10007.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
| -------
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
| extension EFS recovery
| USERENV(1b8.984) 12:06:47:413 ReadStatus: Read Extension's
| Previous status successfully.
| USERENV(1b8.984) 12:06:47:413 CompareGPOLists: The lists
| are the same.
| USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
| and no security group membership change and extension EFS
| recovery has NoGPOChanges set.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
| -------
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
| -------
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
| extension Software Installation
| USERENV(1b8.984) 12:06:47:413 CompareGPOLists: The lists
| are the same.
| USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
| but couldn't read extension Software Installation's status
| or policy time.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension
| Software Installation skipped because both deleted and
| changed GPO lists are empty.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: ----------------
| -------
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Processing
| extension IP Security
| USERENV(1b8.984) 12:06:47:413 CompareGPOLists: The lists
| are the same.
| USERENV(1b8.984) 12:06:47:413 CheckGPOs: No GPO changes
| but couldn't read extension IP Security's status or policy
| time.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Extension IP
| Security skipped because both deleted and changed GPO
| lists are empty.
| USERENV(1b8.984) 12:06:47:413 SetFgRefreshInfo: Next
| Machine Fg policy Synchronous, Reason: SKU.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: No WMI logging
| done in this policy cycle.
| USERENV(1b8.984) 12:06:47:413 LeaveCriticalPolicySection:
| Critical section 0x7d0 has been released.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Computer Group
| Policy has been applied.
| USERENV(1b8.984) 12:06:47:413 ProcessGPOs: Leaving with 1.
| USERENV(1b8.984) 12:06:47:413
| EnterCriticalPolicySectionEx: Entering with timeout 600000
| and flags 0x0
| USERENV(1b8.984) 12:06:47:413
| EnterCriticalPolicySectionEx: Machine critical section has
| been claimed. Handle = 0x7d0
| USERENV(1b8.984) 12:06:47:413
| EnterCriticalPolicySectionEx: Leaving successfully.
| USERENV(1b8.984) 12:06:47:428 LeaveCriticalPolicySection:
| Critical section 0x7d0 has been released.
| USERENV(1b8.984) 12:06:47:428 GPOThread: Next refresh
| will happen in 5 minutes
|
| >-----Original Message-----
| >1. Need more details. What happens when the user logs in?
| Do you get
| >an error message, an access denied etc
| >
| >2. Can you copy paste the profile path you have set here
| >3. Are the users allowed to login to the Terminal Server
| with a
| >default profile? If he can, can the user go to start-run
| and access
| >the
| \\servername\terminalserver_profile_shar_folder\username.
| >
| >4. Enable UserEnvironment Logging on the Terminal Server
| and this
| >would give you a good answer on whats happening in the
| background.
| >Follow this link
| >
| >221833 - How to enable user environment debug logging in
| retail builds
| >of Windows
| >http://support.microsoft.com/default.aspx?scid=kb;EN-
| US;221833
| >
| >5. I can have a look at the UserEnv.Log file if you dont
| find an
| >answer in that.
| >
| >Good luck
| >
| >
| >--
| >Gautam Anand
| >e: gautam@hotpop.com
| >-----------------------------------------
| >
| >
| ><anonymous@discussions.microsoft.com> wrote in message
| >news:2cc701c4a8f9$34f8f330$a401280a@phx.gbl...
| >| Hi,
| >|
| >| I have windows 2003 terminal server configured with a
| >| group policy and set the option (set path for ts roaming
| >| profiles) to create profiles on a share, but for some
| >| reason it's not creating the profile. Any help would be
| >| greatly appreciated.
| >|
| >| John
| >
| >
| >.
| >
- Previous message: Julian Gilbert: "Re: Internet Explorer Maintenance Windows XP SP2"
- In reply to: John Stamos: "Re: set path for ts roaming profiles not creating profile"
- Next in thread: anonymous_at_discussions.microsoft.com: "Re: set path for ts roaming profiles not creating profile"
- Reply: anonymous_at_discussions.microsoft.com: "Re: set path for ts roaming profiles not creating profile"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|