Implementing Roaming User Profiles
To implement RUP for users of Windows Vista and later computers in an AD DS environment, follow these steps:
- Prepare the file server where you want to store roaming user profiles for users by creating a shared folder on the server. (This server is sometimes called the profile server; a typical share name for this shared folder is Profiles.)
- Assign the permissions shown in Tables 1 and 2 to the underlying folder being shared and to the share itself. Also, confirm that the permissions in Table 3 are automatically applied to each roaming user profile folder.
- Create a default network profile for users and copy it to the NETLOGON share on a domain controller. Let it replicate to other domain controllers in the domain. (This step is optional and is typically necessary only if you want to preconfigure a roaming user profile for your users so that they will all have the same desktop experience when they first log on. If you do not create a default network profile, Windows Vista and later versions will use the local %SystemRoot%\Users\Default profile instead.)
- Open Active Directory Users And Computers and configure the profile path on the Profile tab for each user who will roam.
Additional optional steps include configuring roaming profiles as mandatory profiles or as super-mandatory profiles if desired.
Table-1: NTFS Permissions for the Roaming Profile Parent Folder
User Account | Minimum Permissions Required |
Creator/Owner | Full Control - Subfolders And Files Only |
Administrator | None |
Security group of users needing to put data on the share | List Folder/Read Data, Create Folders/Append Data - This Folder Only |
Everyone | No Permissions |
LocalSystem | Full Control - This Folder, Subfolders, And Files |
Table 2: Share-Level Server Message Block Permissions for the Roaming Profile Share
User Account | Default Permissions | Minimum Permission Required |
Everyone | Full Control | No Permissions |
The security groupof the users needing to put data on the share | N/A | Full Control |
Table-3: NTFS Permissions for Each User's Roaming Profile Folder
Table 2: Share-Level Server Message Block Permissions for the Roaming Profile Share
User Account | Default Permissions | Minimum Permission Required |
%UserName% | Full Control, Owner Of Folder | Full Control, Owner Of Folder |
LocalSystem | Full Control | Full Control |
Administrators | No Permissions* | No Permissions |
Everyone | No Permissions | No Permissions |
*This is true unless you set the Add The Administrator Security Group To The Roaming User Profile Share policy, in which case the Administrators group has Full Control (requires Windows 2000 SP2 or later versions).
In this tutorial:
- Managing Users and User Data
- Understanding User Profiles in Windows 7
- Types of User Profiles
- User Profile Namespace
- User Profile Namespace in Windows XP
- User Profile Namespace in Windows Vista and Windows 7
- Application Compatibility Issue
- Disabling Known Folders
- Windows 7 Understanding Libraries
- Working with Libraries
- Including Indexed Folders in a Library
- Adding Nonindexed Remote Locations to a Library
- Creating Additional Libraries
- Managing Libraries
- Implementing Corporate Roaming
- Understanding Roaming User Profiles and Folder Redirection
- Understanding Roaming User Profiles in Earlier Versions of Windows
- Understanding Folder Redirection in Earlier Versions of Windows
- Enhancements to Roaming User Profiles and Folder Redirection Previously Introduced in Windows Vista
- Additional Enhancements to Roaming User Profiles and Folder Redirection Introduced in Windows 7
- Improved First Logon Performance With Folder Redirection
- Implementing Folder Redirection
- Configuring the Redirection Method
- Configuring Target Folder Location
- Configuring Redirection Options
- Configuring Policy Removal Options
- Folder Redirection and Sync Center
- Considerations for Mixed Environments
- Additional Group Policy Settings for Folder Redirection
- Troubleshooting Folder Redirection
- Implementing Roaming User Profiles
- Creating a Default Network Profile
- Configuring a User Account to Use a Roaming Profile
- Implementing Mandatory Profiles
- Implementing Super-Mandatory Profiles
- Managing User Profiles Using Group Policy
- Working with Offline Files
- Enhancements to Offline Files Introduced Previously in Windows Vista
- Additional Enhancements to Offline Files Introduced in Windows 7
- Understanding Offline File Sync
- Modes of Operation in Offline Files
- Managing Offline Files
- Managing Offline Files Using Windows Explorer
- Managing Offline Files Using the Offline Files Control Panel
- Managing Offline Files Using Sync Center
- Configuring Offline Files on the Server
- Managing Offline Files Using Group Policy
- Offline Files Policy Settings Introduced in Windows Vista
- Additional Offline Files Policy Settings for Windows 7