Re: Roaming Profile



Scott <Scott@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
I'm confused on the "timing" of setting roaming profiles.
If I set the profile path *before* a user logs in, isn't the XP
workstation looking for something that is not there?
Wouldn't the requirement be to set to roaming *after* a user logs in?

Thanks.

Hmm - I think you may be a bit confused. You don't actuallychange anything
on the workstation at all, for a roaming profile to work - before or after
login.

If a user logs into the domain and there's a profile path defined in ADUC
for him, his profile is a roaming profile.

The only thing you could change on the workstation is whether that cached
profile is something you want to be updated or not - you can change that
cached copy to a "local" profile, so new logins/logouts won't affect it. I
sometimes do this on a laptop if I don't want the user's desktop to be
modified by laptop-specific stuff.

Here's my boilerplate on roaming profiles -

1. Set up a share on the server. For example - d:\profiles, shared as
profiles$ to make it hidden from browsing. Make sure this share is not set
to allow offline files/caching!
2. Make sure the share permissions on profiles$ indicate everyone=full
control. Set the NTFS security to administrators, system, and users=full
control.
3. In the users' ADUC properties, specify \\server\profiles$\%username% in
the profiles field
4. Have each user log into the domain once from their usual workstation
(where their existing profile lives) and log out. The profile is now
roaming.
5. If you want the administrators group to automatically have permissions to
the profiles folders, you'll need to make the appropriate change in group
policy. Look in computer configuration/administrative templates/system/user
profiles - there's an option to add administrators group to the roaming
profiles permissions.

Notes:

* Make sure users understand that they should never log into multiple
computers at the same time when they have roaming profiles (unless you make
the profiles mandatory by renaming ntuser.dat to ntuser.man so they can't
change them). Explain that the
last one out
wins, when it comes to uploading the final, changed copy of the profile.

* Keep your profiles TINY. Redirect My Documents at the very least; usually
best done to the user's home directory on the server - either via
group policy (folder redirection) or manually (far less advisable). If you
aren't going to also redirect the desktop using policies, tell users that
they are not to store any files on the desktop or you will beat them with a
stick. Big profile=slow login/logout, and possible profile corruption.

* Note that user profiles are not compatible between different OS versions,
even between W2k/XP. Keep all your computers. Keep your workstations as
identical as possible - meaning, OS version is the same, SP level is the
same, app load is (as much as possible) the same.

* Do not let people store any data locally - all data belongs on the server.

* The User Profile Hive Cleanup Utility should be running on all your
computers. You can download it here:
http://www.microsoft.com/downloads/details.aspx?familyid=1B286E6D-8912-4E18-B570-42470E2F3582&displaylang=en


.



Relevant Pages

  • Re: Cant get roaming profiles to work on 1 PC
    ... uploaded to the server where the "Profile Path" is directed. ... I need changes made on the workstation to ... Do this *before* the users' roaming profile folders ...
    (microsoft.public.windows.server.general)
  • Re: Roaming Vs Local User Profile - Win2K3 Server
    ... You are logging on to the XP machines with a domain account you created ... The option to switch to a roaming profile WILL be greyed out at the ... Your only options from the workstation is to tell the workstation NOT to ...
    (microsoft.public.windows.server.general)
  • Re: Roaming Profiles not syncronizing
    ... Ivo try use NetBIOS Name only ... > I have 2 machines joined together with a simple cross-over cable and a KVM> switch, one running Windows Server 2003 Enterprise and the other with XP Professional. ... > The only hassle I'm having is setting up roaming profiles that will> synchronize with the server when the user logs off. ... > Presently the roaming profiles work fine when a user logs on locally to the> server, any changes made are updated to the shared "Profile" folder,, but> when the user logs on to the client machine, the profile loads OK from the ...
    (microsoft.public.windows.server.active_directory)
  • Re: How do I set up a Roaming Administrators Profile?
    ... > privileges after I set them up as a roaming profile. ... I've verified that JOE_ADMIN has admin privileges on the ... > Then, back at the workstation, I log in as Administrator and use the ...
    (microsoft.public.win2000.general)
  • Re: SBS2003 - cannot load local profile
    ... A roaming profile is not a local profile. ... troubled workstation. ... SBS, but as we have a few temporary staff, they may use any unoccupied PC. ...
    (microsoft.public.windows.server.sbs)