Access Denied to Roaming Profiles Share -- Profiles Not Being Created or Used
hi folks!
roaming profiles problem. got windows server 2003-based active directory domain. using roaming profiles users, , existing users having no difficulty. i'm adding batch of new users, however, , cannot roaming profiles work. i've tried creating them manually through ad users , computers using dsadd, , neither works.
basically, create user , specify network location profile directory, in our case \\fileserver\profiles$\%username%. ordinarily, based on past experience, first time user logs in, profile , profile directory automatically created. doesn't happen. no directory created. tried creating profile directory manually myself in advance. still makes no difference. nothing copied directory when user logs in.
normally, not seeing error messages. profiles don't created, copied, etc. however, enabled verbose logging on client , rebooted machine, logged network. after doing so, did roaming profile error @ log on. specifically:
"windows cannot locate server copy of roaming profile , attempting log on local profile. changes profile not copied server when logoff. possible causes of error include network problems or insufficient security rights. if problem persists, contact network administrator.
detail - access denied."
however, if put unc path of profile folder user run dialog, able pull path , have full access add, change, , delete files , folders. have checked permissions both @ share , ntfs levels, , appears correct, based upon recommended settings outlined @ following technet document: http://technet.microsoft.com/en-us/library/cc757013(ws.10).aspx
the kicker, though, if add test user domain admins group, works smoothly. therefore, seem access or permission error, life of me cannot figure out be.
i post screen shots of ad properties test user, , security settings profiles share, i'm not sure see way here attach files. if thinks helpful, let me know , i'll create links screen shots. in short, though, match recommended in document.
any thoughts?
- ithizar
detail - access denied.
seem access or permission error, life of me cannot figure out be.
you correct permissions issue. while technet article worth read confusing @ best, , little overkill in opinion.
per technet article security group of users needing put data on share should domain users.
so according technet ntfs permissions on profiles$ domain users should list folder/read data, create folders/append data.
the share permissions domin users on profiles$ should full control.
personally, drop creator owner on ntfs permissions , assign domain users full control instead....it simplier, little less secure.
Windows Server > File Services and Storage
Comments
Post a Comment