Jump to content

Quick question about redirecting folders


Recommended Posts

Posted

Hi, and sorry for making a new topic!

 

I found a gazillion bits about redirecting folders but didn't find answer for this:

 

We have mandatory user profile for all our students, and they have a home drive on network share. It is currently set up so that My Documents was manually moved to K: drive (their homedir) and updated to the mandatory profile.

 

I read that you guys are using GPO to redirect the My Documents to their homedir. It made me think that is there something wrong in the way it is set up here? :oops:

Posted

You...Don't...Need....Mandatory....Profiles.....With......Active.....Directory.

All you need is a default user profile, either locally on the PC or on a network share. From here just use AD GPO's. When it comes to mapping My Documents to their user area simply set the root path to \\servername\%username% this will then map the my documents folder to one on the relevant server with the users name.

Please guys, just ditch the mandatory profiles eh? Thats what group policy now does.

Posted

@Mark: I think that the reason for nobody descibing the method is that it's so easy and glaringly obvious:

 

1. Leave the profile field empty for all users

2. Use GPOs to redirect the My Documents, Start Menu and Desktop

3. Install all the programs you have and log on as a user with admin rights

4. Run all your programs and configure all the settings - dictionaries, menu options, toolbars, registrations, etc.

5. Copy the folder belonging to the user in step 3 from the local Documents and Settings Folder into the NETLOGON share and rename it to Default User (or copy over the Default User profile on your machines)

6. Live happily ever after.

 

:)

 

(May have missed something but I'm sure that I will be told!)

Posted

Well thanks Ric - that's a start. I already redirect my start menu, and users are configured with h: as my documents [is that a wrong way to do it?? - when bulk adding users i've always set it up with: \\curriculum_server\userhome\%username%\my documents]. Desktop doesn't want to re-direct somehow.

 

But how does this work on multiple machines with different software installs? - do you copy over all profiles on top of the default?

Posted

5. Copy the folder belonging to the user in step 3 from the local Documents and Settings Folder into the NETLOGON share and rename it to Default User (or copy over the Default User profile on your machines)

 

Hi - I use default user settings on the local PC for this - if I put it in the NETLOGON share - which would be applied - local or network??

Posted

[rant]

Yes, I know I have to learn to use the new 2k3 environment properly. I mainly have only done NT4 domains before, and mixed mode in 2k server environment). The work I now have has quite recently upgraded to 2k3 environment (all XP&2k3), and I have to make things work somehow before the students come back from holiday (next monday 8O ).

 

I'll investigate it later on though, even if I'm not putting the new Default User-profile in use. I'll have to think of that, I'm pretty sure that I'm not working here after new year, the unemployment awaits...sigh.

 

Uh oh, better not get started on that :wink:

[/rant]

 

Thanks for the guidance, the thing I've yet to understand from that, is that will it affect the teachers using the computers, and more importanly allow us to easily update the profile with new shortcuts to all users desktop etc. without students messing things up? (we have some different software in different classrooms). Teachers can mess their own profile up, we'll just wipe it and they start clean.

 

Also, what rights would I have to give to redirected start menu and desktop (preferrably I wouldn't put those in place if not necessarily needed), and the new Default User profile on server? Is the NETLOGON share on domain controller or can I put it in our fileserver? Because it it's DC, it's pretty much no go.

 

I'd be glad if anyone can give me another push in the right direction. We have a 2k3 server book, and even it talked about mandatory profiles (must be pretty oldschool book). :)

Posted

@MikeR - The redirected folders you can make read only on the server - so no one can change them.

For different software configurations/start menu's I use loopback processing - although that is deemed slightly evil too I think. It works for me - although it stopped working when something else in the gpo broke - otherwise - no problems.

Posted
Hi - I use default user settings on the local PC for this - if I put it in the NETLOGON share - which would be applied - local or network??

 

Network overrides local.

Posted
@MikeR - The redirected folders you can make read only on the server - so no one can change them.

For different software configurations/start menu's I use loopback processing - although that is deemed slightly evil too I think. It works for me - although it stopped working when something else in the gpo broke - otherwise - no problems.

 

Loopback processing is primarily evil because it slows down the application of GPOs so much when you use it in merge mode. Other than that it's not too serious, just not required for most situations.

Posted

So the Default Local profile get's applied in the absense of a netlogon version.

 

So how else do you get around different start menu's then sahmeepee? - is that in the local profile too? I usually tidy the local machines menu's so that the default is 'safe' - what should I be doing?

Posted
So how else do you get around different start menu's then sahmeepee? - is that in the local profile too? I usually tidy the local machines menu's so that the default is 'safe' - what should I be doing?

 

We don't redirect start menus so I'm not entirely sure what you're trying to do. We install all the software on the PC, move anything unsafe from the "default user" and "all users" start menus into the local admin start menu (just for safe keeping really, the admins can get at unsafe progs via start>run... anyway) then take an image of the PC.

 

If you have something (e.g. SIMS) installed on a pupil machine and you don't want them poking around in the shortcuts for it on the start menu, you can set permissions on C:\Documents and Settings\All Users\Start Menu\Programs\SIMS.net\ via group policy. They'll be able to see the start menu folder, but it'll appear empty when they go to it.

 

Like I say, I'm not quite sure what you need it to do!

Posted
Just wanted to know what you do if you want different start menus - without using loopback. I think you answered my question: it's picked up from the default and all user settings on the local PC. By set permissions you mean making it read only somehow?
Posted

We're almost on the same lines :)

 

I mean: if you set NTFS permissions on a start menu folder and the stuff inside it to (say) "DENY - Full Control" for a domain-wide group containing all pupils, then when a pupil logs in the folder appears to be empty, whereas a teacher would see it as normal.

 

Default User and All Users start menus aren't writable by normal users by default, so they can't screw them up.

Posted

In the past I have just left the 'broken' shortcuts in the start menu - a little untidy but not too bad.

 

I tend to only ever buy site licensed products too because it's a pain in the arse to manage the licenses when you have 30 of this and 15 of that, etc.

Posted
Hi - I use default user settings on the local PC for this - if I put it in the NETLOGON share - which would be applied - local or network??

 

Network overrides local.

 

Well cool! Cheers Geoff - I'll give that a go!

Posted
So the Default Local profile get's applied in the absense of a netlogon version.

 

So how else do you get around different start menu's then sahmeepee? - is that in the local profile too? I usually tidy the local machines menu's so that the default is 'safe' - what should I be doing?

 

You redirect the Start Menus to a place on the server (read only) - I have menus for each Year and another cpouple for teachers - seems to work OK.

Posted

'pologies in advance for the length of this post!

 

What I don't get about not using any form of Mandatory or Roaming profile, is what happens to the local profile when the user logs off. Does it stay there, do you have some kind of startup script to delete them or is there some GP setting that I have never seen which deletes 'standalone' profiles when the user logs off?

 

If the profile is not deleted, then you have no further control over it's content. If you add more software, you need to delete all the local profiles on all the PCs (not a problem I suppose if you still use Ghost). Any damage done to the profile by a student will also persist on the machine in the profile until such time as it is deleted and recreated. I'll assume then that you are deleting local profiles somehow.

 

If the profile is deleted, then a new one will be created each time the user logs on. If this is the case and there is no domain level profile, then all the required software settings need to be in the local default user profile on every machine. Again, somewhat tedious to manage with lots of machines. I'll now assume that a domain level default user profile is the way to go.

 

OK, so you use a domain level Default User profile. You can modify this as necessary and every new profile that gets created will pick up the new settings. Now if this is happening every time a user logs on, then you are no better off than if you were using a Mandatory profile. In fact you are worse off, because you can only have one domain level Default User profile, whereas you can have as many or as few Mandatory profiles as you need.

 

Please feel free to point out what I'm missing !!!

 

For what it's worth, here's how I deal with the problem of different software setups on different PCs...

 

1 - Staff get Roaming profiles and can see the content of the All Users profile. This means they can always see everything on the Start Menu and anything placed on the All Users desktop. As the All Users profile contains data specific to the individual PC, Staff see valid start menu/desktop items on every PC they logon to.

 

2 - Students share one or more Mandatory profiles, but are denied the All Users start menu/desktop. They only see the start menu/desktop which is part of the mandatory profile. The Mandatory profile does NOT contain any extra Start Menu/Desktop shortcuts but read on...

 

3 - When the student logs on (they always get a fresh new profile based on their assigned mandatory profile), the logon script identifies the location of the PC (using an ADSI call which returns the position of the PC in the AD tree). The script then copies down additional Start Menu and Desktop items from a central location on the server. This gives me complete control over the content of student desktops and start menus.

 

4 - When the student logs off, the local copy of the profile is deleted (via GP setting). This means that no matter where the student logs on, they are guaranteed to get the profile that I set up without any changes they may have managed to make to it in their last logon session.

Posted
But I need different start menu's for unique machines. Here I have technology with thier own software set for example - different version of office plus lots of little odd programs - which is why I need different start menu's. I already re-direct but using loopback processing to do it on machine groups.
Posted

@ajbritton: I delete the locally stored profile. Admittedly you still get the network traffic when copying the Default profile but you can keep this relatively small (and it isn't too much of a problem for me cos I use Citrix and I'm using gig links between servers which are all on the same switch).

 

The advantage you do get though, is the disk space saving. Say, for example, a user profile is 6MB (I know it varies but I have seen much bigger!). If you multiply this by 1200, you've used 7GB of disk space!

Posted

@Ric_:

A typical mandatory profile in one of my sites is no more than a couple of MB and I generally have no more than one per academic year (total size = 15MB tops!).

 

There is a GP setting which can limit the size of roaming profiles. I would point out that, if you are redirecting Application Data to a server, you are still storing most of the profile content anyway. If you are not redirecting Application Data, then you don't have anything like the same functionality as roaming profiles. Also, if space is a concern, (ooh those hard disks are SO expensive - NOT!), there are GP settings which allow you to control which parts of a profile actually roam (ie get copied to the server).

 

Daniel Petri has some useful tools for writing CMD style logon scripts which need to determine Group or OU membership.

  • 2 weeks later...
Posted
@ajbritton: Sorry to come back to this, but what's the point in the mandatory profiles if the program groups, etc. are all pulled from the server via a login script?
Posted
@ajbritton: Sorry to come back to this, but what's the point in the mandatory profiles if the program groups, etc. are all pulled from the server via a login script?

That's OK Ric, always happy to talk about profiles!!

 

Basically the answer to your question is two things;

 

1 - User registry (HKEY_CURRENT_USER) which is stored in the NTUSER.MAN file. Some apps need settings present to work correctly.

 

2 - Application Data folder. Again, some apps need files here to work correctly.

 

Before you (or anyone else) says it, yes I know I could keep these things in the Default User profiles (either at domain or worktation level), but I prefer to keep those as clean as possible. Also, every time you make a change to a Defau;t User profile, the render all existing profiles out of date. That means they have to be deleted and recreated (doable by script, I know). Using the mandatory profile means I don't have to worry about getting rid of any local profiles from PCs.

 

As others have pointed out, it's horses for courses, but It seems to me that not using Mandatory profiles (a mechanism specifically designed for managing locked down environments) and having to fart about with scripts to delete profiles makes life a lot more complicated.

 

A final point is that it is possible to have as many or as few different Mandatory profiles as are required. There is only one domain level Default User profile (or only one per PC). I can configure different Mandatory Profiles for different year groups if necessary.

 

Hope this answers your question. Incidentaly, these are the sort of questions that led me to suggest the creation of a WIKI to draw together everyone's experience and knowledge of what profiles/roaming/mandatory/temporary are, how they work and how they can be used.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...