Jump to content

Recommended Posts

Posted

There's no security risk. You're adding users as local workstation administrators. This permits domain users using applications, (who are not domain administrators), to write locally. Many applications require this to run properly.

 

Using GPOs you hide/deny access to C:\ from Explorer, but applications, such as MS Word can write/cache information locally as they normally would in a standalone environment.

Posted
There's no security risk. You're adding users as local workstation administrators. This permits domain users using applications, (who are not domain administrators), to write locally. Many applications require this to run properly.

 

Using GPOs you hide/deny access to C:\ from Explorer, but applications, such as MS Word can write/cache information locally as they normally would in a standalone environment.

 

Ah, ok... but I think you may have gone off at a tangent from what I'm trying to achieve here, ie: delete/remove the auto-recovery documents that have not been deleted.

Posted

@contink - I understand where you're coming from, however the reason for my suggestion is because you're using roaming profiles and this is written locally to a workstation when a user logs on (as I am sure you know).

 

Whilst using various applications, these applications will write/cache information locally, such as Auto Recovered Files, unless you specify another location using GPOs. Adding "Domain Users" may fix your problem, as it allows applications to cache/write/delete information as it needs to. Hope this makes sense.

Posted
@contink - I understand where you're coming from, however the reason for my suggestion is because you're using roaming profiles and this is written locally to a workstation when a user logs on (as I am sure you know).

 

Whilst using various applications, these applications will write/cache information locally, such as Auto Recovered Files, unless you specify another location using GPOs. Adding "Domain Users" may fix your problem, as it allows applications to cache/write/delete information as it needs to. Hope this makes sense.

 

Ah... ok... that makes a lot more sense... I wasn't 100% sure about whether the roaming profile would get written to the local machine or not (call it momentary paranoia :p) but that confirms things.

 

There is however one small twist here and that's the problem where this all comes from in the first place.. Namely these autorecovery docs appear on accounts where they logon whole classes. Add this to individuals not logging off properly all the time and I can resolve the problem on the local profile but never clean the remote profile because someone never quite clears off.

 

Thinking about it, it may be that I need to just run the script of the profile folders when everyone is pretty much off and if it crops up again I can search for the offending PC/individual.

 

 

Just out of interest on the Local Admin things... would not adding them to the Local "Power Users" group have much the same effect?

Posted

I would recommend you download Ork Tools (Office Resource Kit) for Office. Office 97/2000/XP/2003 and 2007 all have their own versions

 

Once you've loaded the Office ADM templates into your GPOs, you can then begin tweaking policies as you do with Windows. They'll be autosave/autorecover policies you can set.

Working on the presumption all users have their My Documents mapped as a network drive (for example H:\), the autosave/autorecover files will appear here instead.

 

As for adding Domain Users as local Power Users instead of local Administrators, you could try, however I am not entirely sure what the results would be.

  • 3 weeks later...
Posted

Er...has anyone come up with a definitive answer to this? I have been hunting everywhere but can find nothing that works, and the TA who is stuck with all these docs is going berserk!

So, if you can help....?

thanks

Posted

I haven't forgotten... honest, it's just this incessant ringing in my ears... Oh the phone, that's it... :p

 

I think I have most of the info' so I'll see if I can't dummy something up shortly... Just keep bugging me or my memory sort of wanders off.

  • 1 month later...
Posted

Hello Contink - anyone in there?

 

I am slowly sinking under a sea of recovered docs.

I have now been told that it isn't that anyone is logging on or off or saving improperly, rather that it is because we have 30 machines logged on as the same user. Microsoft doesnt like it, it seems

Posted
Hello Contink - anyone in there?

 

I am slowly sinking under a sea of recovered docs.

I have now been told that it isn't that anyone is logging on or off or saving improperly, rather that it is because we have 30 machines logged on as the same user. Microsoft doesnt like it, it seems

 

I've got a clearer idea of what's happening but been somewhat distracted trying to get my CIS kits ready for launch...

 

I'll see if I can write something up this week and test it when I'm in school on Thursday. Bug me Friday and I should have some news.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...