XP Clients, NT4 Domain, NO AD - group policy question

From: Jack Knight (none_at_spamto.dev.null)
Date: 12/23/04


Date: Thu, 23 Dec 2004 11:30:12 GMT

Hi,

I have the following scenario:

XP Pro (SP2) laptops
NT4 Domain.
Roaming Profiles.

I need to lock down individual users on the machine, whilst allowing
administrators to do pretty much anything.

I created a group policy with gpedit for the local machine locking down
all the required items, then prevented read access to that policy to the
administrators group with an explicit DENY acl. Works fine at the local
level, new users get all required lockdowns, admins get everything they
need.

However when the machine joins a domain and a user who has never before
logged on to that machine does so, their roaming profile appears to
completely overwrite/override the local machine policy, and also cause
other weird effects like items on the start menu from "All Users"
disappearing, which I cannot find a way to put back.

Is there a way to allow only certain parts of the roaming profile (e.g.
mail server settings, IE proxy info etc.) to be loaded into the local
profile, but prevent my carefully crafted start menu and settings being
blatted?

This happens for both normal users and admins.

There is also the spectre of some users having mandatory profiles.

Any help greatly appreciated.

JK



Relevant Pages

  • Who understands gpresults?
    ... I'm trying to enable logon to "(local machine)" with a profile that is both ... a roaming profile and a locally cached copy. ... Assignment" on the default domain policy. ...
    (microsoft.public.windows.server.active_directory)
  • Re: undeleted user profile and home dir
    ... Are you saying that after deleting the roaming profile, ... network share, or that a profile on a local machine was still present. ...
    (microsoft.public.win2000.active_directory)
  • What does a roaming profile download on load?
    ... When a user logs in and their computer downloads a roaming profile, ... the whole profile downloaded to the local machine, ...
    (microsoft.public.windowsxp.general)
  • Copying Local to Roaming Profile
    ... I'm in the process of switching user & computer accounts from an NT4 domain ... using the roaming profile), background has been reset, some start menu items ... are gone, IE favorites are gone, installed app settings are gone, etc. ...
    (microsoft.public.windows.server.general)
  • XP Client/NT4 Domain/Group Policy Question
    ... NT4 Domain. ... I created a group policy with gpedit for the local machine locking down ... administrators group with an explicit DENY acl. ... logged on to that machine does so, their roaming profiles appear to ...
    (microsoft.public.windowsxp.help_and_support)