Re: Repost: GP is ignored, users settings vanish

From: Fred_B (FredB_at_discussions.microsoft.com)
Date: 02/17/05


Date: Thu, 17 Feb 2005 14:55:04 -0800

Thanks for the reply.

Sorry, I'm not sure what you mean master?
If you mean the directory with all of the individual user profiles in it,
that's got permissions set domain users > full control. The root of the drive
is the same.

Fred

"Roger Abell" wrote:

> Check the NTFS permissions on the master of their roaming
> profile. It sounds as if they are only getting access to their
> profile due to a grant to Administrators and/or Domain Admins.
> When their membership is removed, the profile cannot be read,
> and the system creates a new one.
>
> --
> Roger Abell
> Microsoft MVP (Windows Security)
> MCSE (W2k3,W2k,Nt4) MCDBA
> "Fred_B" <FredB@discussions.microsoft.com> wrote in message
> news:9D38C496-225D-41FF-83A6-92A7BE3C0D70@microsoft.com...
> > Hi,
> > Two problems here I think...
> >
> > To cut to the chase I've created a new OU for certain users who already
> > exist in the default Users group. The users are both domain
> > admins and domain users. They do not need to be domain admins.
> > I have created a new OU for them, which has a group policy applied to it
> to
> > prevent them switching off screensaver passwords etc nothing overly
> > restrictive.
> > All users use roaming profiles.
> >
> > In a test, I've moved test users to the new OU, and at the same time
> removed
> > them from the domain admin group.
> >
> > When the test users logon, Windows treats them as if they've never logged
> on
> > before. Personal settings such as mapped drives, shortcuts etc are gone,
> the
> > connect to
> > the internet icon pops onto the desktop along with the welcome to windows
> > dialog and all of the default shortcuts on the start menu.
> > Also the group policy doesn't apply...
> > If I leave them in the new OU but make the user a domain admin again, the
> > personalized settings come back and the group policy applies OK.
> > Their settings come back if I move them back to the original users
> > container, obviously GP doesn't apply here.
> >
> > In the group policy, authenticated users and domain users are both set to
> > read and apply group policy.
> > In my previous post, I was directed to what permissions were on the
> roaming
> > profiles directory. Domain users have full control.
> >
> > This making any sense to anyone?
> >
> > Fred (Confused)
> >
> >
>
>
>



Relevant Pages

  • Re: Intermittant GPO failure to apply
    ... After checking your group policy, we also need to check your event log, ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... | that doesn't have an ntuser.pol file anywhere, maybe roaming profiles ...
    (microsoft.public.windows.server.sbs)
  • Re: Roaming Profile Setup Problem.
    ... Steve Efferin typed: ... Does this has anything to do with the group policy? ... Another issue is when I tried to set up the Folder Redirection, ... I am trying to setup Roaming Profiles for the Active Directory ...
    (microsoft.public.windows.server.setup)
  • Re: Mandatory Profile Nightmares!
    ... Does the CSE client need to be install on the Windows 2003 servers in my ... Group Policy on the Windows 2008 DC. ... I have all of my users set to create their own profiles in a network ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Roaming Profile Setup Problem.
    ... Does this has anything to do with the group policy? ... Another issue is when I tried to set up the Folder Redirection, ... I am trying to setup Roaming Profiles for the Active Directory ...
    (microsoft.public.windows.server.setup)
  • RE: Deleteing Local profiles
    ... Assuming you are running windows 2000/2003, try using group policy it will ... folder redirection for the users desktop and start menu and redirect them to ... > implement roaming profiles. ...
    (microsoft.public.windowsxp.security_admin)

Loading