我遇到一些严重的问题,导致一组用户停止使用漫游configuration文件。
正如预期的那样,我已经在域中启用了漫游configuration文件。 – 但我在做GPO过滤,限制了范围。 我最初设置为authentication用户进行漫游,但是由于域已经分支到多个地点,我只把范围限制在中央局附近的人。
我所链接的GPO已过滤到我创build的组中,其中包括我不想拥有漫游configuration文件的用户。 此GPO位于域的根目录,启用了“强制”设置,因此它应覆盖下面的任何设置。 *在旁注中,这是我刚刚设置为“强制”的唯一GPO。
我知道GPO正在工作,因为我可以看到在漫游configuration文件下login的用户的原始registry设置 – 然后在组策略更改后login的同一用户,registry反映了本地configuration文件。
但不幸的是,即使在进行这些设置之后 – 用户在其中一台服务器上获得漫游configuration文件。
在下面的代码块中列出了同一用户帐户的gpresult(在更新后的gpo之后)。 您可以在该输出的顶部看到,它实际上处理漫游configuration文件。 – 当然,在为漫游configuration文件托pipe文件共享的服务器上,它会在用户login后为用户创build一个文件夹。
出于testing目的,我删除了用户个人资料的所有副本,漫游和本地。 但是问题还在这里。 – 所以我在组策略设置中更宽泛地忽略了一些东西。
有人能指点我在这里失踪的方向吗?
***** gpresult / r *****
Microsoft(R)Windows(R)操作系统组策略结果工具v2.0版权所有(C)Microsoft Corp. 1981-2001
创build于2010年5月15日上午8:59:00
OSconfiguration:成员工作站操作系统版本:6.1.7600站点名称:N / A漫游configuration文件:\ ***** \ profiles $ *****本地configuration文件:C:\ Users *****连接缓慢链接?
CN=*****,OU=*****,OU=*****,OU=*****,DC=*****,DC=***** Last time Group Policy was applied: 5/15/2010 at 8:52:02 AM Group Policy was applied from: *****.*****.com Group Policy slow link threshold: 500 kbps Domain Name: USSLINDSTROM Domain Type: Windows 2000 Applied Group Policy Objects ----------------------------- ForceLocalProfilesOnly InternetExplorer_***** GlobalPasswordPolicy The following GPOs were not applied because they were filtered out ------------------------------------------------------------------- DAgentFirewallExceptions Filtering: Denied (Security) WSAdmin_***** Filtering: Denied (Security) NetlogonFirewallExceptions Filtering: Not Applied (Empty) NetLogon_***** Filtering: Denied (Security) WSUSUpdateScheduleManualInstall Filtering: Denied (Security) WSUSUpdateScheduleDaily_0300 Filtering: Denied (Security) WSUSUpdateScheduleThu_0100 Filtering: Denied (Security) AlternateSSLFirewallExceptions Filtering: Denied (Security) SNMPFirewallExceptions Filtering: Denied (Security) WSUSUpdateScheduleSun_0100 Filtering: Denied (Security) SQLServerFirewallExceptions Filtering: Denied (Security) WSUSUpdateScheduleTue_0100 Filtering: Denied (Security) WSUSUpdateScheduleSat_0100 Filtering: Denied (Security) DisableUAC Filtering: Denied (Security) ICMPFirewallExceptions Filtering: Denied (Security) AdminShareFirewallExceptions Filtering: Denied (Security) GPRefreshInterval Filtering: Denied (Security) ServeRAIDFirewallExceptions Filtering: Denied (Security) WSUSUpdateScheduleFri_0100 Filtering: Denied (Security) BlockFirewallExceptions(8400-8410) Filtering: Denied (Security) WSUSUpdateScheduleWed_0100 Filtering: Denied (Security) Local Group Policy Filtering: Not Applied (Empty) WSUS_***** Filtering: Denied (Security) LogonAsService_Idaho Filtering: Denied (Security) ReportServerFirewallExceptions Filtering: Denied (Security) WSUSUpdateScheduleMon_0100 Filtering: Denied (Security) TFSFirewallExceptions Filtering: Denied (Security) Default Domain Policy Filtering: Not Applied (Empty) DenyServerSideRoamingProfiles Filtering: Denied (Security) ShareConnectionsRemainAlive Filtering: Denied (Security) The user is a part of the following security groups --------------------------------------------------- Domain Users Everyone BUILTIN\Users BUILTIN\Administrators NT AUTHORITY\INTERACTIVE CONSOLE LOGON NT AUTHORITY\Authenticated Users This Organization LOCAL *****Users VPNAccess_***** NetAdmin_***** SiteAdmin_***** WSAdmin_***** VPNAccess_***** LocalProfileOnly_***** NetworkAdmin_***** LocalProfileOnly_***** VPNAccess_***** NetAdmin_***** Domain Admins WSAdmin_***** WSAdmin_***** ***** ***** Schema Admins ***** Enterprise Admins Denied RODC Password Replication Group High Mandatory Level
我只是忽略了AD中简单的configuration文件位置设置。 Craptastic。
现在已经修好了