Jump to content

Default profile and GPOs EDIT: Now how to install hotfix


Recommended Posts

Posted

Hi,

 

We're just setting up a Win2k3 domain and are having a bit of trouble with profiles. We started off using Mandatory profiles for the kids, but then found out that it was overriding any new GPOs that were set, so we've decided to go roaming, locking down with group policy. However, I also found out that if I create a Default User profile in the NETLOGON folder, that too overrides GPOs (well, at least the proxy settings GPO that I've been testing it with). Log on to a machine with a test student user that downloads the default profile, and they have filtered proxy settings - fine. Log off, delete their profile, change the GPOs so that unfiltered proxy settings are attached to their OU and remove the filtered ones, log on, download the default profile and the filtered settings still apply. Anyone have any ideas?!

 

Joe

Posted

The default profile is used to create new profiles. Thus it has no effect on existing profiles. Therefore what happens:

 

1. new user logs in

2. windows makes a new profile using the default profile

3. user logs out.

4. user logs in again.

5. existing profile is used.

6. group policies are applied.

7. user logs out.

8. go to step 4.

 

Also, bear in mind there is a 90min delay before workstations pick up GPO settings changes.

Posted
I should have stated that Fast Boot is off, so group policy is refreshed every time the user logs on - it shows up in a gpresult which is the most bizarre thing. And step 5 doesn't happen because I deleted the local profile in between the user logging out and in again so they would download the default profile again.
Posted

Fast boot has no bearing on the 90min update delay.

 

Group policies are applied before the default user profile is copied. Which is why you aren't seeing their affects.

 

Stop deleting local profiles or use mandatory profiles instead.

Posted
It doesn't for the computer policies (unless you restart the computer) but the user policies it certainly does - as I said, the gpresult I did showed that the new policy came into effect. So by your theory, if I don't delete the user's profile, the new GPOs will be applied when they next log in? Mandatory profiles unfortunately have the same problem, which is why I want to move to roaming.
Posted

btw, you might want to start using the GPMC rather than gpresult. It makes diagnosing these problems a lot easier.

 

Basically the 'Way to do it'™. Is to setup a default user profile on either your machine image (ghost, ris, whatever) or to have one in the netlogon. Then everything else you can't set up globally in the default profile must be put in group policies. There's no need for mandatory or roaming profiles with this approach.

 

After a couple of logins everything should be working fine.

 

However, that said, mandatory profiles can be used to much the same effect. Especially for kids. Where you want everything to be the same and tight control over settings that aren't controlled via GPO settings.

 

It really comes down to personal preference and what your comfortable with.

Posted

I think I've actually found the solution - when I created the mandatory and default profiles I was logged on to a machine with a Domain User, so group policy was being applied. I just created a profile with a local user (so no group policy was being applied) and uploaded that, and it seemed to work. I'll test it more thoroughly, but I think that's fixed it - I'll just stick with my mandatory profiles.

 

Oh, and I was using GPMC to actually create and manage group policy, but gpresult on a machine that's having problems is incredibly useful, to see what policies are actually being applied.

 

Thanks for talking it through with me!

 

Joe

Posted

Ah, I didn't know that. It is sitting right next to me though, so it doesn't make much difference!

 

Ok, well it's not working. Not entirely sure whether it was in the first place - maybe it was all just a figment of my imagination...

 

Anyway, so downloading the mandatory/default profile (they're both pretty much the same) now results in me not being able to get on the internet at all. I think it's only the IE branding that's not working because all the other policies seem to be unaffected. If I just pick up the local default profile, then it works fine.

Posted

I don't know if this helps, but I've found that if you have a mandatory profile and apply Group Policy, the Group Policy will not apply unless the user is an administrator on the local computer. GPResult will say that it applied the policy, but the settings will not apply.

 

Related to this, I've also found that if the profile that you move to the default user on a local computer had a Group Policy applied to it(domain or local), then the policy will continue to apply to any profile that gets created from the default user, and GPResult will never show it being applied! I've made a point for the technicians to only copy the local administrator's profile (no domain GPOs) before any local GPO is created if they want to tweak the default user profile settings. Otherwise we end up with "ghost" group policy settings being applied.

 

Maybe what you're experiencing is related to either of those situations.

Posted

The 'ghost' group policy settings is exactly the situation we're in. However, I found that if you create the default/mandatory profile from a local user rather than a domain user, there are no 'ghost' GPOs.

 

However, I haven't experienced your first comment - as far as I can see, all policy is being applied correctly except the IE branding.

 

Thanks for the link Geoff - that looks like the thing I've been after. Pity I have to phone up MS to get the hotfix :( I'll have a look at it tomorrow.

 

Have a good evening!

 

Joe

Posted

I use mandatory profiles and have no problems with Group Policies applying to them.

 

When making a Mandatory or Default User profile, you MUST MUST MUST use the GUI to copy the profile.

 

When copying the Mandatory or Default User profile, make sure you set the 'allowed to use' to Everyone. If this is not done, then the eventual user of the profile will not have the necessary permissions to write policy settings into the profile.

 

It is not enough to copy the folder from C:\Documents and Settings. The GUI allows you to change the permissions on the profile. The permissions are NOT JUST on the files which the profile is made up of, but also in the registry which is stored in NTUSER.DAT. Changing the file permissions on NTUSER.DAT do NOT affect the regitry permissions therein.

Posted
Funny you should mention. After wasting 30mins before I came home today on a new Staff profile that wont apply. I remebered half way home that copying it with the GUI isn't enough I should set permissions first.... oops
Posted
I remebered half way home that copying it with the GUI isn't enough I should set permissions first

 

eh??? Is this a typo?

 

When I talk about copying with the GUI, I'm referring to the section under My Computer Properties, Advanced, User Profiles where the local profiles are listed and may be copied.

Posted
Thanks very much for the link to the hotfix Geoff - I phoned up Microsoft this morning and received the fix which seemed to work. Now I just have to figure out a way of deploying it to a few hundred machines...
Posted
Ok, this really shouldn't be hard. I have a hotfix. It is an .exe. How do I deploy it to my 500 odd machines automatically? I can't deploy it through SMS because it's neither an MSI nor a proper Windows Update (and I haven't got the inventory enabled anyway, and can't be bothered to find out how unless someone has a nice easy step-by-step guide), nor can I seem to install it by running it at startup. What do I have to do?!?!?!
Posted
I have had a look at that. They only help if I could figure a way of running the update successfully on a machine from a remote location though.
Posted
That's pretty much exactly the same script as I wrote (except I couldn't get the script to read the files from my file server, so I actually put them in the policies folder). Unfortunately it doesn't work. At least I don't think it does - I'll have another go now.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...