Jump to content

TBFC

Members
  • Posts

    4
  • Joined

  • Last visited

Reputation

5 Neutral

About TBFC

  1. We have a Gemalto setup for Barclays/BACS, and it is fiddly. What works for us, when we're asked to assist, is: Also, I believe we've had some luck running it through Chrome, which also installs a plugin. Edge is right out.
  2. From when we first rolled out Windows 10 with folder redirection, we ran into issues with various Creative Cloud apps launching. Different apps got to different stages, but it was at least a problem with Premiere Pro and InDesign. It wanted to use AppData, Documents and the C: profile, and any attempts we made at redirecting them caused the student to be unable to launch them, with them crashing during the "Loading" splash screen. I'd be up for replacing everything with redirected folders and local profiles (after some investigation), but without having proper controls to remove them from the machine on log-off, we're just going to be running into the same issues again.
  3. Hi all, We've been having an ongoing fight with machines with trying to get them to respect what we're setting up, either through ignoring GPOs or just changing behaviour. Students: Our students use Mandatory profiles. We did have an issue last year where Chrome did not work, due to an issue with it interacting with a cryptographic service, but that has been resolved. All machines are now running Windows 10 1809, Enterprise. Intended behaviour: A student logs in, receives the shared mandatory profile. Does work, signs out. Machines delete the user profile on log-off. Policy in place to delete user profiles older than 1 day, to catch any others. Roughly six months ago, on 1803, this worked. Actual behaviour: A student logs in, receives the shared mandatory profile. Does work, signs out. The profile stays on the machine (200MB each, minimum). On logging in again, it uses that profile. If there is ever an issue with that profile, it prevents them logging in with a "Group Policy" error - "Cannot load profile", which means their profile must be manually removed from the registry. The issues we're running into are students not being able to log in (due to the profile error), machine hard drives filling up and students saving work to the machine, rather than network storage (we can't redirect Documents/Appdata due to Creative Cloud throwing a wobbly). Policies configured for the profiles: Public Key Policies/Certificate Path Validation Settings/Stores[url="http://www.edugeek.net/"]hide[/url] [TABLE="class: info"] [TR] [TH]Policy[/TH] [TH]Setting[/TH] [/TR] [TR] [TD]Allow user trusted root Certificate Authorities (CAs) to be used to validate certificates[/TD] [TD]Disabled[/TD] [/TR] [TR] [TD]Allow users to trust peer trust certificates[/TD] [TD]Enabled[/TD] [/TR] [TR] [TD]Peer trust certificate purposes:[/TD] [TD]Client Authentication; Secure Email; Encrypting File System[/TD] [/TR] [TR] [TD]Root CAs that client computers can trust:[/TD] [TD]Third-Party Root Certification Authorities and Enterprise Root Certification Authorities[/TD] [/TR] [TR] [TD]For certificate-based authentication of users and computers, along with CAs that are registered in Active Directory, the client computer must use should also use user principal name (UPN) constraint compliant CAs[/TD] [/TR] [TR] [TD]Disabled[/TD] [/TR] [/TABLE] System/User Profiles[url="http://www.edugeek.net/"]hide[/url] [TABLE="class: info3"] [TR] [TH]Policy[/TH] [TH]Setting[/TH] [TH]Comment[/TH] [/TR] [TR] [TD]Add the Administrators security group to roaming user profiles[/TD] [TD]Enabled[/TD] [TD][/TD] [/TR] [TR] [TD]Delete cached copies of roaming profiles[/TD] [TD]Enabled[/TD] [TD][/TD] [/TR] [TR] [TD]Delete user profiles older than a specified number of days on system restart[/TD] [TD]Enabled[/TD] [TD][/TD] [/TR] [TR] [TD="colspan: 3"] [TABLE="class: subtable_frame"] [TR] [TD]Delete user profiles older than (days)[/TD] [TD]1[/TD] [/TR] [/TABLE] [/TD] [/TR] [TR] [TH]Policy[/TH] [TH]Setting[/TH] [TH]Comment[/TH] [/TR] [TR] [TD]Do not forcefully unload the users registry at user logoff[/TD] [TD]Disabled[/TD] [TD][/TD] [/TR] [TR] [TD]Do not log users on with temporary profiles[/TD] [/TR] [TR] [TD]Enabled[/TD] [/TR] [/TABLE] Staff members: Staff members use Roaming profiles and have a separate set of User OUs and Machine OUs. On first logon, with no network profile, the Start Menu (list of programs, not tiles, redirected via GPO) appears as expected. On second logon, or a logon to a new machine, the Start Menu only contains the automatically-added programs (Mixed Reality, Photos, Cortana...). Deleting the NTUSER.dat file from the staff member resolves the issue as long as they are using machines they have a profile on. Going to a new machine requires the deletion again. Folder Redirection is set up for all document folders and libraries, to their Network Home Drive. ExcludeProfileDirs is set up with "AppData\Local;AppData\LocalLow;$Recycle.Bin". Unfortunately I'm at a loss on where to go next, for both issues. Students were fixed and working, and as far as I can see should work ("Delete user profiles older than 1 day" is pretty explicit...). Staff members, everything I try to look up leads me to issues about the Tiles, which we do configure, but I'm much less concerned about. Has anyone encountered these before, or have any idea where to go from here? I've heard rumblings around Roaming and Mandatory profiles being phased out for... something else, but I've never seen anything explicit on what to do instead - running without profiles just fills the local drives. Many thanks!
  4. Hi all, Over the past week we've had reports from staff members getting incomplete Start Menus. Unfortunately, both the frequency of occurrences and the actual effects are inconsistent. We've been using the same method for Start Menus for over a year now. Staff members use roaming profiles, with all of AppData/Local denied for roaming. The Start Menu directory is copied to C:\Win10StartMenu\, and redirected to that location via GPO. The reason for this is that laptops taken off-site were losing the start menu. The issue we are seeing is, for some users, the Start Menu does not contain all the folders and shortcuts it should. They will only have folders down to a certain level (eg: They'll have Adobe Creative Cloud, Internet Browsers, but not Microsoft Office or Utilities). However, the directory where the shortcuts are stored does contain all of the shortcuts. Normally, we can add a shortcut to the C:\Win10Start Menu, then the Start Menu picks it up instantly. This is now not the case. We do have an issue where, on the second login, the Start Menu list does not populate at all. The 'fix' is to remove the user's ntuser.dat from the server, after which they work normally. This doesn't resolve the issue. We are not seeing this issue with our Student or Exam accounts, which use mandatory and local profiles respectively. Removing the local and server profile does not resolve the issue. I have once seen a series of command windows appear, saying "Path cannot be found" (or similar), before disappearing. Changing the Start Menu redirection to point at the server rather than local (to try and avoid a clash between copying and reading) does not resolve the issue. There don't seem to be any entries in Windows Logs that relate to the issue. Unfortunately we can't do rapid testing, due to the intermittent nature of the issue, so any help would be appreciated. Many thanks!
×
×
  • Create New...