talksr Posted May 3, 2018 Posted May 3, 2018 Hi there, I have a 2016 server, I am trying to redirect all users to a shared desktop with fixed icons (word, excel etc). I have set up the policy and verified that the path is accessible from the computers, which it is, but when I login with any user account, their own personal desktop is showing. I am using roaming profiles for users. Any ideas?
Liam Posted May 3, 2018 Posted May 3, 2018 Is the user in the test ou you have configured? Everything looks right in gp. Are you permissions set correctly in your share? 1
Liam Posted May 3, 2018 Posted May 3, 2018 Check there are no other policies that are taking priority too. Is there any loopback configured on the computer ? Group policy result it to see what’s going on 1
snagrat Posted May 3, 2018 Posted May 3, 2018 Check event log on client PC. It will log Folder Redirection successes and failures 1
talksr Posted May 3, 2018 Author Posted May 3, 2018 Check there are no other policies that are taking priority too. Is there any loopback configured on the computer ? Group policy result it to see what’s going on Have even tried adding individual users to the Security Filtering part but it has not helped. Here is the results of the GPResult: GPReport.zip It isn't showing in applied policies. Can't make it out.
Liam Posted May 3, 2018 Posted May 3, 2018 Check the delegation tab. Have you got any settings in there to deny it? Try creating a new policy as a test 1
Liam Posted May 3, 2018 Posted May 3, 2018 When you apply security filtering check that authenticated users appears in the delegation tab too. Had that before
talksr Posted May 3, 2018 Author Posted May 3, 2018 (edited) Check the delegation tab. Have you got any settings in there to deny it? Try creating a new policy as a test Delegation all looks fine. Authenticated Users is in Sec Filtering by default on this server (not sure if it is 2016 default) so no worries there. Just created new policy, same thing again. Testing computer is 100% in the right OU. Just can't understand what the issue is. Edited May 3, 2018 by talksr
smarties11 Posted May 3, 2018 Posted May 3, 2018 Testing computer is 100% in the right OU. Just can't understand what the issue is. Folder redirection policies are user policies, not computer policies. Your GPO needs to be linked to a user OU, and your test user needs to be located in the same OU. From your quote above it sounds like you've linked the GPO to a computer OU. 1
Liam Posted May 3, 2018 Posted May 3, 2018 Folder redirection policies are user policies, not computer policies. Your GPO needs to be linked to a user OU, and your test user needs to be located in the same OU. From your quote above it sounds like you've linked the GPO to a computer OU. The image shows it’s in user. The reason he’s checking computer ou is if there is loopback configured
smarties11 Posted May 3, 2018 Posted May 3, 2018 The image shows it’s in user. The reason he’s checking computer ou is if there is loopback configured I wouldn't be so sure. Image shows the policy settings are in User Configuration, but it doesn't confirm that the policy is linked to an OU containing a user. Given that GPResult shows nothing and he's mentioned that the computer is in the right OU, my money is on this policy being linked to an OU containing the test computer, rather than an OU containing a test user? 1
BenJSmith Posted May 4, 2018 Posted May 4, 2018 If you need an alternative - try it via registry key. I have found more success using the User Shell Folders keys than I have with the folder redirection policy.
Liam Posted May 7, 2018 Posted May 7, 2018 If you need an alternative - try it via registry key. I have found more success using the User Shell Folders keys than I have with the folder redirection policy. [ATTACH=CONFIG]48820[/ATTACH] Is this faster? I have had to copy folders locally for best performance and quickest login
talksr Posted May 8, 2018 Author Posted May 8, 2018 Folder redirection policies are user policies, not computer policies. Your GPO needs to be linked to a user OU, and your test user needs to be located in the same OU. From your quote above it sounds like you've linked the GPO to a computer OU. The image shows it’s in user. The reason he’s checking computer ou is if there is loopback configured Hi there, just to clarify, it is configured under User Configuration: Apologies Liam, I have not had a chance to get back to you yet, it has been so busy here, just a nightmare. We are also now getting issues whereby the user logs in and gets a black screen, no icons, no taskbars etc. Got to say, for my first Vanilla Windows 10 system, I am far from impressed. Nothing seems to be working. Have checked event viewer and we seem to have a couple of failed GP MSI installs:
talksr Posted May 8, 2018 Author Posted May 8, 2018 (edited) Furthermore, for some reason, for any login, on any computer is displaying a C:\ folder on the desktop. When you click on it, it takes you to what looks like C:\users on the local computer. Don't know how, or where this is coming from. If I delete it, it just keeps coming back. It is doing it for normal office users, admin users, anyone. What I have found is that if you click on users, there is only an administrator folder within this folder which is not right. Look at the properties for the folder, it isn't C:\users, it is a folder within the profile. Edited May 8, 2018 by talksr
smarties11 Posted May 8, 2018 Posted May 8, 2018 Hi there, just to clarify, it is configured under User Configuration: [ATTACH=CONFIG]48843[/ATTACH] Sorry to be like a dog with a bone on this, but you are missing my point. I could see you have done it under 'user configuration' on your original screenshot. That is not what I am questioning. I am questioning whether you have this group policy linked to an OU that actually contains users. Your previous comment about the "computer being in the correct OU" might imply that you have actually linked the policy to an OU containing computers.....which won't work. So, your OU 'bgfa.internal/Testing OU' - what is in this OU when you look at it in AD? Your test computer, or your test user? I'll bow out at this point as I don't want to seem like I am hassling you, but I suspect that is why your policy isn't applying or showing in GPRESULT..... 1
Steve21 Posted May 8, 2018 Posted May 8, 2018 Hi there, just to clarify, it is configured under User Configuration: What he means though was if it's set as a user policy is it applied to a user OU not a Computer OU etc (Not sure what the "Test" one includes) Steve 1
PyROm Posted May 8, 2018 Posted May 8, 2018 Others above were saying that if you are trying to apply the gpo object itself to the computer branch of ad rather than the user branch (ie. you have linked the gpo object to an ou with computers in it rather than users), then it will ignore the user settings section of your gpo. To get round this you need to enable loopback policy mode under administrative templates->system->group policy->loopback policy. If you use impero there is a list of exceptions you need to put into impero server, this is discussed in the impero forum on edugeek.
Steve21 Posted May 8, 2018 Posted May 8, 2018 Furthermore, for some reason, for any login, on any computer is displaying a C:\ folder on the desktop. When you click on it, it takes you to what looks like C:\users on the local computer. Don't know how, or where this is coming from. If I delete it, it just keeps coming back. Seems like you have a few issues going on here. Where are those files/shortcuts you linked on the picture from? If it's redirected successfully it should show the redirected one, else it should show their local desktop which wouldn't have those on. Or are you using roaming desktop profiles as well? Steve
talksr Posted May 8, 2018 Author Posted May 8, 2018 Sorry to be like a dog with a bone on this, but you are missing my point. I could see you have done it under 'user configuration' on your original screenshot. That is not what I am questioning. I am questioning whether you have this group policy linked to an OU that actually contains users. Your previous comment about the "computer being in the correct OU" might imply that you have actually linked the policy to an OU containing computers.....which won't work. So, your OU 'bgfa.internal/Testing OU' - what is in this OU when you look at it in AD? Your test computer, or your test user? I'll bow out at this point as I don't want to seem like I am hassling you, but I suspect that is why your policy isn't applying or showing in GPRESULT..... Others above were saying that if you are trying to apply the gpo object itself to the computer branch of ad rather than the user branch (ie. you have linked the gpo object to an ou with computers in it rather than users), then it will ignore the user settings section of your gpo. To get round this you need to enable loopback policy mode under administrative templates->system->group policy->loopback policy. If you use impero there is a list of exceptions you need to put into impero server, this is discussed in the impero forum on edugeek. Seems like you have a few issues going on here. Where are those files/shortcuts you linked on the picture from? If it's redirected successfully it should show the redirected one, else it should show their local desktop which wouldn't have those on. Or are you using roaming desktop profiles as well? Steve Ah right ok, ok. Thank you everyone. Sorry, I was missing the point re the policy being in an OU with actual users. It isn't. I have just linked my Desktop Redirection policy into my Admin Users OU, which contains all of the users. Just rebooting a machine and I will re-test. I don't believe we have loopback enabled. Is this in the Computer Config or User Config Group Policy folder within the policy? Lastly, we are using roaming profiles.
BenJSmith Posted May 8, 2018 Posted May 8, 2018 I've had no issues at all - we have used it in the past for shortcuts and such, never had any issues. 1200+ users.
smarties11 Posted May 8, 2018 Posted May 8, 2018 ..... I think it has done the trick..... [ATTACH=CONFIG]48852[/ATTACH] Excellent! Also....roaming profiles are a bit of a no-no with Windows 10. It doesn't support them correctly. There is a reg hack you can do to get them working 99% but they still won't work with Start Menu XML layouts if you want to use those. I think they work OK with the LTSB 1607 build but you'll only have the same issue when LTSB moves to the latest build in 2019. Best to plan ahead now. You'll need to move to local or mandatory profiles and then use U-EV to roam the user settings. 1
talksr Posted May 8, 2018 Author Posted May 8, 2018 (edited) Excellent! Also....roaming profiles are a bit of a no-no with Windows 10. It doesn't support them correctly. There is a reg hack you can do to get them working 99% but they still won't work with Start Menu XML layouts if you want to use those. I think they work OK with the LTSB 1607 build but you'll only have the same issue when LTSB moves to the latest build in 2019. Best to plan ahead now. You'll need to move to local or mandatory profiles and then use U-EV to roam the user settings. Ok, interesting. I am afraid, I am still having issues. Now, I am getting the desktop, which is great. But, the icons are only working for the computer I copied the icons from originally to put in the desktop icons folder that each computer looks at to get the shortcuts. If you use any other computer, you now get this, which is useless: So I have now made the issue even worse as users are now unable to access anything. Do you suggest I forget about the roaming profiles as I do also want to use Smart Menu XML layouts? The problem is that some users have quite large profiles due to using MS Outlook and having mailboxes over 1gb in size. Edited May 8, 2018 by talksr
Steve21 Posted May 8, 2018 Posted May 8, 2018 I'm assuming those computers have the same software installed on? If it's not installed yet it wouldn't show the icons etc, and will take a while after it's installed to reinitialise the cache etc. The other option is are you mixing 32bit and 64bit setups as could be wrong shortcuts if so? Steve
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now