Jump to content

Recommended Posts

Posted

Hello everyone, I am a new system administrator in the K12 sector. Do you have any free alternatives to mandatory profiles for Windows 10 and 11 machines? I am having difficulty setting up mandatory profiles, permissions on ntuser.dat, and file associations. So we have 20 computers in the computer lab and one computer for each classroom. Teachers teach one class and then move on to the next, and so on.

What are you using in your schools?

Posted

As above, local profiles - there's so little that needs storing these days anyway it's not worth doing much else. Faster too if you're not forcing profiles to redirect to a network share.

Posted

Thank you guys for the fast replies. How would you implement this? Like, for example, Professor X enters the classroom and finds the computer already turned on and logged in, with the default icons (Chrome, Adobe, etc.) on the desktop. If they download files from Chrome, I would like them to remain only for that professor and not be visible to others in the next class. How do you manage this? 

Posted

We use local profiles but with Desktop/Start Menu and My Docs redirected to network shares. Start menu and Desktop is shared read only, and My Docs goes to the users home drive (although we're pushing most things to OneDrive, there's still some things that windows wants local, like Downloads). This seems to work pretty well for us (although first logins can take a bit longer).

 

If you want staff to be able to customise their deskops then you could just redreicte them all to the user's home drive. So Professor X gets his desktop from \\server\Share\ProfX\Desktop and his my docs from \\server\share\ProfX\Documents and so on. Then when Magneto logs in (sorry couldn't help myself), he gets his own desktop/documents at \\server\sahre\magneto\... 

Posted
37 minutes ago, sledpath said:

Thank you guys for the fast replies. How would you implement this? Like, for example, Professor X enters the classroom and finds the computer already turned on and logged in, with the default icons (Chrome, Adobe, etc.) on the desktop. If they download files from Chrome, I would like them to remain only for that professor and not be visible to others in the next class. How do you manage this? 

Why would the computer already be logged in? Surely they would log in with their credentials so that they get their own profile created and log off at the end of the session?

  • Like 1
Posted (edited)
2 hours ago, sledpath said:

Thank you guys for the fast replies. How would you implement this? Like, for example, Professor X enters the classroom and finds the computer already turned on and logged in, with the default icons (Chrome, Adobe, etc.) on the desktop. If they download files from Chrome, I would like them to remain only for that professor and not be visible to others in the next class. How do you manage this? 

Not using individual logins???

 

Redirected Desktops are a great method. Students can have a shared (good for putting a link on the desktop and more control) and staff can have individual per account.

 

One thing to note with a desktop is that for every link/file it will also try and locate the icon so not best practice to save lots to the desktop and it gets messy.

Edited by Davit2005
Posted
1 hour ago, ThatBoringBloke said:

Why would the computer already be logged in? Surely they would log in with their credentials so that they get their own profile created and log off at the end of the session?

Sorry, I meant they logon with their AD credential as they do now (of course without the path of mandatoryfolderprofile.v6) 

Now I am testing the usage local profiles, I see the appdata folder growing fast. How do you deal with that? Our SSD are 128 gb

Posted
Just now, sledpath said:

I see the appdata folder growing fast. How do you deal with that? Our SSD are 128 gb

Best option is a combination of buy bigger hard drives for computers that have lots of users and regular deletion of older profiles (can be scripted/semi-automatic)

Posted
13 minutes ago, Davit2005 said:

 

One thing to note with a desktop is that for every link/file it will also try and locate the icon so not best practice to save lots to the desktop and it gets messy.

As of now, students and theacher use the same folder for thier desktop (C:\Users\Public\Desktop) so they can't delete the shortcut. This is good for our setup

Posted
2 minutes ago, sledpath said:

Sorry, I meant they logon with their AD credential as they do now (of course without the path of mandatoryfolderprofile.v6) 

Now I am testing the usage local profiles, I see the appdata folder growing fast. How do you deal with that? Our SSD are 128 gb

128GB depending on use is not going to last long. I did manage to exclude certain files for redirection but that was a long time back, like 10+ years. Iphones and the like if they are backed up will likely take huge amounts of space.

Posted (edited)
5 minutes ago, sledpath said:

As of now, students and theacher use the same folder for thier desktop (C:\Users\Public\Desktop) so they can't delete the shortcut. This is good for our setup

I think you will find that the shared is only going to be for things like Program shortcuts, not really good to have a shared desktop for staff where they can save documents to the desktop and other staff be able to access them openly even for students for that matter. The room for some serious issues is huge.

Edited by Davit2005
Posted
15 minutes ago, Davit2005 said:

I think you will find that the shared is only going to be for things like Program shortcuts, not really good to have a shared desktop for staff where they can save documents to the desktop and other staff be able to access them openly even for students for that matter. The room for some serious issues is huge.

How do you manage this then?

Posted

We have been using local profiles for a few years, It really helps to spped up logon times.

 

I have an extra mapped drive which has shortcuts for apps / websites that will not go onto the start menu.

 

Posted

Just to add another thing into the mix, we're using UE-V (User Experience Virtualisation) which for the most part is local profiles with some settings copied back to a "profile" on a server. What gets copied back is never particularly large with the largest profile being a couple of hundred KB. It can be larger if you allow users to set their own desktop wallpaper as it will copy whatever is set back to the profile folder but we have one of two backgrounds applied on login depending on whether the user is Staff or Students, but this doesn't get copied back and keeps the server profile very small.


It just means that if users want to set their computer experience up a certain way i.e. if you have left-handed users (or one-armed users!) then it'll set the mouse to left-handed on every computer they login to, without the complexity/large file sizes of Roaming profiles.

For us, login times are still as long as it takes to create a local profile on a machine but somewhere in the background, it still applies saved settings.

Posted

Has Microsoft updated its advice regarding multi user PCs where there may be hundreds of local profiles stored.

 

First login times with modern apps being installed is still a big issue on slower machines.

 

With LTSC being not recommended what are people doing as work arounds?

 

Chrome OS handles this much better as it automatically clears the local user cache when local storage is low.  Also first logins are much faster.

Posted
5 minutes ago, Alis_Klar said:

First login times with modern apps being installed is still a big issue on slower machines.

Currently our mandatory profile logon speed is around 15 to 20 seconds on windows 11 i5 12400 8 gb ram 128 gb ssd, a bit longer (around 30 seconds) on older pc running windows 10

Posted
On 10/03/2026 at 11:54, Alis_Klar said:

With LTSC being not recommended what are people doing as work arounds?

 

It would seem that MS has changed its stance on this...

 

Possibly realising the massive need of businesses and educational establishments for a work ready OS without all the bloatware...?

 

"Windows 11 Enterprise LTSC 2024 builds on Windows 11 Enterprise, version 24H2 adding premium features designed to address the needs of large and mid-size organizations (including large academic institutions), such as advanced protection against modern security threats, full flexibility of OS deployment, updating and support options; as well as comprehensive device and app management and control capabilities. The LTSC edition provides customers with access to the Long-Term Servicing Channel as a deployment option for their special-purpose devices and environments, with quality updates provided for a full 5 years"

 

For those crying about how LTSC should only be used in nuclear power plants, you will have to be upset at those who have managed to get IOT licenses now and not those of us who wanted an OS without Candy Crush, XBox, etc.

  • Like 1
Posted

For many years we have had Desktops (read only with basic shortcuts that users need), Documents (with Videos, Pictures, and Music nestled inside) and Downloads redirected to our file servers.  This keeps the local profiles from getting too big.  Users do not have access to the C drive at all.

 

So far so good.

Posted (edited)

Configure Storage Sense with local profiles. Have profiles be removed from the device if not logged in in x amount of days to keep storage clean.

Edited by EssentialRug
  • 1 month later...
Posted

You have a the option of redirecting appdata.  Before you get excited, this will only redirect "%appdata%\roaming" so not the big hitter \local    dont try to use the registry bodges to redirect \local  it will end in pain. Plus you cant redirect the onedrive cache folder either so dont try that (even with custom locations) it simply isnt supported and wont work (no you cant use tricks such as symbolic links either, they arent supported by onedrive either).  You can also redirect downloads too.  Note that both of these will still work with known folder redirection enabled for onedrive.

 

Failing that, look at FSlogix, in a nutshell that redirects all the profile to a network share (this is a very simplified explanation of what it does).  You might be licensed to use it and will solve "large profile" issues since they will be stored on a network server.

Posted

If you are redirecting appdata you may want to exclude certain paths. We had users who'd backed up their iPhones to there desktops and this equated to a sizeable chunk. I cannot remember how we did it as it was over 10 years ago now.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...