Kyle Posted September 7, 2006 Posted September 7, 2006 Can some one help with ideas on this. Staff have a laptop, which we set up on the network ans also put on a local user. The staff can log on to the local user when they are at home or away from the network and use their normal network log on account when on the network. We share the local users 'MY Documents' so that their network user account can save files to it so they can work from home. Is their anyway i can stop then from being able to logon tho their network account, when away from the network, I believe XP lets you log on 8-10 times with the memory cache from the network, Is it possible to stop them from logging on to the network account when at home?
Ric_ Posted September 7, 2006 Posted September 7, 2006 EDIT: Just re-read the post and I was talking rubbish... a little late maybe last night! The following still stands though Conversly, why not scrap the local user and simply use the cached user profile and offline files? This works very well for me and my lusers love it.
GrumbleDook Posted September 7, 2006 Posted September 7, 2006 You can set it so that if it doesn't find a roaming profile (run delprof on logout) then it will not allow them to login. We do this on classroom machines now, but have tested it on laptops too (classroom laptops so the students cannot login if the wireless is down ... or just turned off on the laptop is the usual thing). Not sure of the exact locations in the GPO though ... I'll ask my NM to post tomorrow (if noone beats him ... which people usually do ... )
Kyle Posted September 7, 2006 Author Posted September 7, 2006 Ok, I found it Computer config>admin templates>system>user profiles. two settings 1. Delete cached copies of local profiles 2,Log off users when roaming profile fails. Well i have this set to enabled on the default Domain Policy and i know it works on PC's in the school and also on laptops. Little confused. I have two more OU's one called Computers which has the machines in and one called Staff which has the staff in. I thought anything in the Default Domain Policy settings overrides anything below. The reason i ask this is because in the Computer OU and Staff OU the above settings are not configured. Do I need to enable the settings in those OU as well or should the Domain OU do this automatically? I have never been too sure on how the OU GPO's inherit from one above?(still on huge learning march)
alan-d Posted September 8, 2006 Posted September 8, 2006 I thought anything in the Default Domain Policy settings overrides anything below. Nope it's the other way around - any gpo below the default take precedence and computer settings take precedence over user settings (Most of the time! :? ) It can get even more confusing but that's the very basic way it works
Geoff Posted September 8, 2006 Posted September 8, 2006 Use the GP Results and GP Modelling (only avalible with W2k3 DCs) in the GPMC to see how things get combined together for specific user and computer combinations.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now