ITGURU Posted September 11, 2019 Posted September 11, 2019 I have 1 site of which folder redirection works flawlessly. I'm setting this up at another site and have an issue. All GPO's are set up exactly the same way at both sites. At the site with an issue, when users login, under quick links , the My Pictures link works fine, its goes to the 'my pictures' in their home directory folder. However for Downloads and Documents, when you click the link it comes up with 'this operation has been cancelled due to restrictions in effect on this computer. In event viewer the error says: Failed to apply policy and redirect folder 'documents' to N:\ can't create folder N:\ This security ID may not be assigned as the owner of the object. I have a test user which it works for (user created a long time ago) and that works, documents redirects to the home folder. However all other users cannot use 'documents' however all users are in the same OU, same policies applies, and home directories on the same server with same permissions compared between the working and all other non working accounts. Any help would be appreciated as users have to keep clicking off the error to gain access to documents. Thanks.
Oaktech Posted September 11, 2019 Posted September 11, 2019 your restriction error is because the redirection is not in place and you've rightly restricted access to the C drive which is the fall back location (C:\users). Have you set the homedrive location in AD? That usually creates the folders with the right permissions but you need to do that before you start seriously using the redirection as it overwrites permissions that are there. What do the permissions actually look like? can you screen shot and blank out the advanced permission panel?
ITGURU Posted September 11, 2019 Author Posted September 11, 2019 yes, the homedrive location in Ad is \\servername\username$ Folder redirect IS in place in the GPO. - if i remove it, the user which does work then reverts back to C:\users so know it's working. permissions below on home directory. compared against a working user - both have exactly the same share and NTFS permissions obviously apart from the users username which is the only difference between the 2.
Oaktech Posted September 11, 2019 Posted September 11, 2019 I meant that the redirection is not in place at the client device, because it's failed, if you clear the error, right click on documents and then go to location for a non working user, I'll bet the location says C:\users Is the working user being redirected from the same GPO? I'm just thinking about a random scope issue? Adding domain computers read to the permissions of the GPO sometimes helps with random issues like this. Let me have a think about it.
Oaktech Posted September 11, 2019 Posted September 11, 2019 yes, the homedrive location in Ad is \\servername\username$ Folder redirect IS in place in the GPO. - if i remove it, the user which does work then reverts back to C:\users so know it's working. permissions below on home directory. compared against a working user - both have exactly the same share and NTFS permissions obviously apart from the users username which is the only difference between the 2. [ATTACH=CONFIG]54924[/ATTACH] Can you click through to the 'owner' tab and see what that says?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now