Jump to content

Recommended Posts

Posted

We have a problem with our roaming profiles (which are used for staff only) on windows 7 and was wondering if anyone can offer any advise.

 

I have got a group policy setting which redirects the users Documents, favourites, pictures, music, videos and desktop to their userarea. The setting in Group Policy is set to redirect to \\server\share\%username%\documents... \%username%\desktop .... \%username%\favourites. So i create a new user from scratch (i shall call the user "TESTUSER")... putting in the profile location and userarea.

 

When the user logs on, i can see the documents, desktop and favourites folders created in the userarea.

 

Now the problem comes on windows 7 when i click Start > {name of user} (this been TESTUSER) and it displays the local folders for this user. From here if i double click documents, it redirects me to the userarea... the same with favourites and desktop so i know folder redirection is working.

 

Now this is where the fun begins... so say i have clicked Start > TESTUSER and i create a folder in this area (im not to sure what this area is called, so i will call it the local profile), the folder will be stored in the users profile, meaning if they create lots of files and folders in here thinking that this will be their userarea their profile is going to be huge.

 

1. How do i stop users from saving things in here...

2. is there a way i can redirect {name of User} link from the start menu to directly point to the userarea rather than the local profile

 

When the user logs off, i can see that the profile has been updated on the profile server store.. but i cannot access it, so, I make sure that the group "staff" has full access and the TESTUSER is a member of staff, thinking this would work.. but no... when i log back into the system with TESTUSER i get a nice litte message saying that the profile could not be read and that it is using a previous profile.. Now when i log off, the profile is not updated on the server... and the files in the local profile of the machine stay there without being copied over.

 

Why is this so awkward? With XP, it was so straight forward.

Posted

This is intended behavior. When you click the username from the start menu it shows the root of the local copy of the user's profile folder. This root folder is no longer hidden from the user, but is instead available for use. There is absolutely no way to prevent this with roaming profiles. You cannot do it with folder permissions or group policies.

 

Creating files and folders in this root profile folder instead of one of the redirected folders will cause them to be syned to the server copy of the user's profile.

Posted
so what is the work around??? or isnt there one? I keep thinking that win7 is more aimed at the home market rather than the corporate market...
Posted
This makes me want to check our config now, I know i've not had any problems with this. Denying access to the C: drive may at least prevent them from accessing the location.
Posted
so what is the work around??? or isnt there one? I keep thinking that win7 is more aimed at the home market rather than the corporate market...

 

BINGO, the reason I will keep XP on my systems till W8 comes out

Posted
While testing out some stuff for terminal services I did have some success using group policy preferences to delete the local folders as the user logs in so they aren't seeing a local one and a redirected one.
Posted

What you need to do is create a default user profile in the root on netlogon on your domain controller, then delete all the local folders in this profile that you have redirected using group policy, then when the user logs on and gets the new profile they will not have duplicate local folders. ( you could also do this to the mand profile of the users if this is what you use instead of creating a default user profile.

 

Also to prevent users saving files into the local root area of thier profile enable the below group policy for those users.

 

 

 

Group Policy

 

Navigate to User Configuration, Administrative Templates, Windows Components, and then select Windows Explorer in the left column of the Group Policy editor.

 

Double-click Prevent users from adding files to the root of their Users Files folder in the Settings section of the Group Policy editor.

 

Select Enable and then click OK to save the changes.

  • Thanks 1
Posted
BINGO, the reason I will keep XP on my systems till W8 comes out

 

Hmmm, ive seen windows 8 on youtube and just looked at it now on the bbc site... it seems to me like they are keeping the same file system, so i think the same problem will exist...

Posted
What you need to do is create a default user profile in the root on netlogon on your domain controller, then delete all the local folders in this profile that you have redirected using group policy, then when the user logs on and gets the new profile they will not have duplicate local folders. ( you could also do this to the mand profile of the users if this is what you use instead of creating a default user profile.

 

Also to prevent users saving files into the local root area of thier profile enable the below group policy for those users.

 

 

 

Group Policy

 

Navigate to User Configuration, Administrative Templates, Windows Components, and then select Windows Explorer in the left column of the Group Policy editor.

 

Double-click Prevent users from adding files to the root of their Users Files folder in the Settings section of the Group Policy editor.

 

Select Enable and then click OK to save the changes.

 

This doesnt work if you are saving documents... even though you cannot make new folders, you can still save documents liek word, excel, pdf, serif files etc...I cannot believe that no one has found this problem

Posted
...I cannot believe that no one has found this problem

 

Well I don't think that is true, I have this issue as well, but sometimes there isn't an easy solution.

 

If you want a non-easy solution, make a user log-off script that checks the local profile folder for files which shouldn't be there and move them to their shared area instead.

Posted
This doesnt work if you are saving documents... even though you cannot make new folders, you can still save documents liek word, excel, pdf, serif files etc...I cannot believe that no one has found this problem

 

wells that's strange because we cannot when this is set and has worked for quite a few schools i have helped get setup on windows 7, there must be somthing strange on your systems .

Posted

The chances are im wrong... but have you tried deleteing the local profile? then restarting then logging in again

 

or remove the profile path in active directory and see if it works? at least that way you can find out if its the computer or the profile

Posted
The group policy setting prevents you from saving into the "user" folder, but not into the actual folder which the user folder points to. So that means you can save in c:\Users\joe.bloggs folder but you cannot save into the "Joe Bloggs" user folder even though it points to the same place.
Posted

I noticed this on my Win 7 test PC, thought it would sort out with 2008 managing the workstations (stuck on 2003 at the moment until we move our DCs to virtualised) but looks like a poorly thought out design unless we're all missing something?

 

Is there a GPO to hide the USERNAME item from the Start Menu and just see Documents, Pictures etc? Saying Access Denied when trying to save into a viewable folder just sounds like a good way to get lots more support calls when we move over :p

Posted (edited)

Ok, so i have tried all the suggestions on this thread but still no joy...

 

I have attached a pic to show which area i would like disabling. The only problem is when a user clicks on save in a word doc it defaults to the desktop but when you click the users name it goes the local profile... which i can see most users doing here.

 

EDIT: Its not jsut word documents, its everything PDFs, smartboard files... etc

Test.png

Defaulting to desktop.png

Edited by timbo343
Posted

You wont be able to stop it completely, there are system files in this folder that the user must be able to read/write/create, this is just how windows 7 works. This was always there on windows xp and it was the same problem then, the only difference is that it wasn't presented to the user in quite such an obvious way.

 

To that end, I think your best hope now is to just hide it so the user cannot ever browse to it. You can remove it from the start menu and desktop using the usual group policies and you can remove it form the file save dialogs by doing this:

 

Hide User Folder on Save as Dialog Box - TechNet Forum Windows 7 Support Team - Site Home - TechNet Blogs

  • Thanks 1
  • 3 weeks later...
Posted
You wont be able to stop it completely, there are system files in this folder that the user must be able to read/write/create, this is just how windows 7 works. This was always there on windows xp and it was the same problem then, the only difference is that it wasn't presented to the user in quite such an obvious way.

 

To that end, I think your best hope now is to just hide it so the user cannot ever browse to it. You can remove it from the start menu and desktop using the usual group policies and you can remove it form the file save dialogs by doing this:

 

Hide User Folder on Save as Dialog Box - TechNet Forum Windows 7 Support Team - Site Home - TechNet Blogs

 

Thanks for this... This was the solution i used and added a shortcut on the users desktop to point to their userarea so if they need to save there they can do

  • 7 months later...
Posted
Just bumping this one, I'm guessing there's still no fix for the users' named folder in the Start Menu?

 

I believe this is the GPO you're looking for:

 

User Config > Policies > Admin Templates > Start Menu and Taskbar - Remove user folder link from Start Menu - Enabled

  • Thanks 1
Posted
so what is the work around??? or isnt there one? I keep thinking that win7 is more aimed at the home market rather than the corporate market...

 

Windows 8 is going to be a small release by the looks of things. There aren't that many changes, so Windows 8 will be Windows 7 + tablet functionality.

 

There are a lot more GPOs you can set with Windows 7 compared to XP. I am presuming you're running 2008 R2 to get the best out of Windows 7?

Posted

You could disable Libraries but personally I would leave well alone. I've setup quite a number of networks with Libraries enabled with no problems. Users are also familiar with Libraries as Windows 7 is starting to gather speed with user popularity. Many users are now using Windows 7 at home.

 

Libraries are new to Windows 7, just like the new Start Menu was new to XP and many went back to the classic Start Menu. In Windows 7 you're now forced to use a revised version of XP's/Vista's Start Menu and I suspect eventually Libraries will become the standard in Windows 8 onwards.

Posted
You could disable Libraries but personally I would leave well alone. I've setup quite a number of networks with Libraries enabled with no problems. Users are also familiar with Libraries as Windows 7 is starting to gather speed with user popularity. Many users are now using Windows 7 at home.

 

Libraries are new to Windows 7, just like the new Start Menu was new to XP and many went back to the classic Start Menu. In Windows 7 you're now forced to use a revised version of XP's/Vista's Start Menu and I suspect eventually Libraries will become the standard in Windows 8 onwards.

Id rather have gpo to specify more so i could add shared work drives as a library or even quickly create ones when 2 kids work together

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...