Petri IT Knowledgebase Forums
 

Petri.co.il forums Home Forums Start Page Forums Frequently Asked Questions FAQ Member List Members List
Go Back   Petri IT Knowledgebase Forums > Server Operating Systems > Windows Server 2000 / 2003
Petri.co.il is happy to award auglan the title of Most Valuable Member !!!
Register Calendar Calendar Search Petri IT Knowledgebase Forums Search Todays Posts Today's Posts Mark Forums Read

Notices

setting up profiles and homedirs - procedure

setting up profiles and homedirs - procedure

this thread has 2 replies and has been viewed 1375 times

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 2nd May 2007, 15:11
spoofer spoofer is offline
Casual
Casual
 
 Join Date: Oct 2006
  6 month star 12 month star
 Posts: 48
 Reputation: spoofer is on a distinguished road (20)
Default setting up profiles and homedirs - procedure

Hello,

I'm looking for the right procedure to implement roaming profiles and homedirs.
Currently i set up a home test lab with a server and a client

I made a script that creates my OU's and users.
Now when it creates the users, it grabs the data from an excel spreadsheet.
I also included a line in this script that automatically sets the path to the profile and the homedir
(\\server\userData\homes$ and \\server\userData\profiles$)
I shared these two folders (share permissions - read)

1) Does this folder need everyone - Full Control ?

Now i want to use these account, so logon from a client with a random user account
What i thought would happen is, the user profiles gets created and gets copied to the profiles folder on the server, same for the homedir.

Now when i logon from the client this goes very slow, too slow i think.
So is there something wrong with the way i set it up ? If so, what am i doing wrong ?

Thanx in advance everyone.
  #2  
Old 2nd May 2007, 15:23
jasonboche's Avatar
jasonboche jasonboche is offline
Moderator
 
 Join Date: Apr 2006
  6 month star 12 month star
 Location: Minnesota
 Posts: 1,539
 Send a message via ICQ to jasonboche
 Reputation: jasonboche is just really nicejasonboche is just really nicejasonboche is just really nicejasonboche is just really nicejasonboche is just really nice (409)
Default Re: setting up profiles and homedirs - procedure

Quote:
Originally Posted by spoofer View Post
Hello,

I'm looking for the right procedure to implement roaming profiles and homedirs.
Currently i set up a home test lab with a server and a client

I made a script that creates my OU's and users.
Now when it creates the users, it grabs the data from an excel spreadsheet.
I also included a line in this script that automatically sets the path to the profile and the homedir
(\\server\userData\homes$ and \\server\userData\profiles$)
I shared these two folders (share permissions - read)

1) Does this folder need everyone - Full Control ?
A. Never use the "everyone" group

B. The roaming profiles share (and underlying NTFS permissions) will need to be ACLd for modify permissions for the user ID who owns the folder. It does not need full control. That's another thing to stay away from. Granting your users Full Controll allows them to play with NTFS permissions and that's a recipe for their own demise. The only one who ever needs full control is an administrator. I have yet to ever come across an application that would need full control. At most they will need MODIFY. The only 2 things that FULL CONTROL gives someone beyond MODIFY is the ability to change permissions and the ability to take ownership of files and folders.

C. If that data folder is their home folder, you are going to need more than just READ permissions on that guy too. MODIFY should do the trick.

Quote:
Originally Posted by spoofer View Post
Now i want to use these account, so logon from a client with a random user account
What i thought would happen is, the user profiles gets created and gets copied to the profiles folder on the server, same for the homedir.

Now when i logon from the client this goes very slow, too slow i think.
So is there something wrong with the way i set it up ? If so, what am i doing wrong ?

Thanx in advance everyone.
__________________
VCDX3 #34, VCDX4, VCDX5, VCAP4-DCA #14, VCAP4-DCD #35, VCAP5-DCD, VCPx4, vEXPERTx4, MCSEx3, MCSAx2, MCP, CCAx2, A+
boche.net - VMware Virtualization Evangelist
My advice has no warranties. Follow at your own risk.
  #3  
Old 2nd May 2007, 15:42
spoofer spoofer is offline
Casual
Casual
 
 Join Date: Oct 2006
  6 month star 12 month star
 Posts: 48
 Reputation: spoofer is on a distinguished road (20)
Default Re: setting up profiles and homedirs - procedure

Quote:
Originally Posted by jasonboche View Post
A. Never use the "everyone" group

B. The roaming profiles share (and underlying NTFS permissions) will need to be ACLd for modify permissions for the user ID who owns the folder. It does not need full control. That's another thing to stay away from. Granting your users Full Controll allows them to play with NTFS permissions and that's a recipe for their own demise. The only one who ever needs full control is an administrator. I have yet to ever come across an application that would need full control. At most they will need MODIFY. The only 2 things that FULL CONTROL gives someone beyond MODIFY is the ability to change permissions and the ability to take ownership of files and folders.

C. If that data folder is their home folder, you are going to need more than just READ permissions on that guy too. MODIFY should do the trick.
Ok so what i basicly have to do is
1) create the needed groups (place global groups in domain local groups, where i put the permissions on)
2) place the domain local groups in the share acl for both the folders
3) set the share permission to change

is this correct ?

// ok i did the steps as above and think there is still something wrong

Now the folder for the user gets created in the profiles folder on my server
But on the client side, i keep seeing, Loading personal data (setting up the new profile on the server probably ?)

For NTFS permissions on both the folders
I just had to add the correct group to the ACL of the homes share and give that usergroup modify, right ?
Profiles share just needed the standard NTFS permissions ?

Last edited by spoofer; 2nd May 2007 at 16:24..
Closed Thread


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Sysvol folder empty after Replica procedure wilbur Windows Server 2000 / 2003 2 24th April 2007 17:16
NT--2003 migration step by step procedure or checklist?? sharwal Windows Server 2000 / 2003 2 22nd March 2007 04:43
Setting up Windows server w/ roaming profiles hawee Misc 2 8th October 2006 05:16
Backup and RESTORE procedure for Citrix Server Rex Terminal Services 1 15th March 2006 08:36
How To Change Defalut Setting of Sound Recorder Setting in WindowXP. Mandeep Singh Windows 2000 Pro, XP Pro 1 30th December 2005 16:17


All times are GMT +3. The time now is 17:13.

Steel Blue 3.5.4 vBulletin Style ©2006 vBEnhanced
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
 

Valid XHTML 1.0!   Valid CSS!

Copyright 2005 Daniel Petri