Friday, June 27, 2008

Windows2003:Roaming profile on Laptop computers

Before the laptop joins the domain, the laptop user: kevin.smith has a local profile. In the local profile, outlook was set with pop3 account.

After the laptop joins the domain, Kevin Smith has a domain account: Kevin.Smith@TLCTest.local. This account has its profile set to [\\servername\share\kevin.smith] --roaming.

Please don't log on from laptop as kevin.smith yet!!!!

First, modify the laptop computer's local policy settings.
Local Computer Policy--Computer Configuration--Administrative Templates--System--User Profiles
  • Prevent Roaming Profile changes from Propagating to the server: disabled
  • Only allow local user profiles:disabled
In the domain controller, modify the default domain controller policy to grant Kevin.Smith "Allow Log on locally".

At the domain controller, log on as Kevin.Smith and log off Kevin.Smith. The roaming profile is created.

Then, from laptop computer, log on as Kevin.Smith. You will find the Kevin.Smith uses the roaming profile now. If you logged on as Kevin.Smith in the Laptop before you log him on to domain controller, kevin.smith is always using its local profile.

Copying local profile over the roaming profile

Log on as the administrator on laptop computer.
Copy Kevin.Smith's local profile over the roaming profile and don't forget granting the TLCtest.local\Kevin.smith the access permission.

However, the profile copying process will not copy the Local Settings folder in Kevin.Smith local profile. By default, outlook pst file is created under Local Settings folder.

If you know the pop3 account password, that would be easy. If not, you should manually copy the folder: %systemroot%\documents and settings\Kevin.Smith\Local Settings\Application Data\Microsoft\Outlook folder to Kevin.Smith.TLCTEST\Local Settings\Application Data\Microsoft\Outlook folder.

If Kevin.Smith has the signatures, you should copy the folder: %systemroot%\Documents and Settings\Kevin.Smith\Application Data\Microsoft\Signatures to the folder: Kevin.Smith.TLCTEST\Application Data\Microsoft\Signatures.

I assigned Kevin.Smith with FULL CONTROL to Kevin.Smith.TLCTest and granted Kevin.Smith@TLCtest.local the FULL CONTROL to Kevin.Smith.

But if the domain user name is different to the local user name, you must provide the pop3 password even though you do all the above steps.

Domain user name: blue
Local User name:Kevin.Smith


=========





Cannot change a local profile to roaming profile


User NIFCS\Twoodworth has logged in to domain for over a year. She uses local profile all the time. After I set her domain account profile path with [\\nifcs-main\profile\%username%] and recycle the logon/off process many times, she still uses the local profile --only. I cannot change it manually, as shown below.


Solution and danger:


Thank GOD, I copy the NIFCS\twoodworth local profile to another folder. Please turn on "Show Hidden Files/Folders" and copy everything from NIFCS\Twoodworth to another folder, in case something goes wrong.


After the account profile path is configured, logon/off the domain controller as twoodworth, then log on as administrator and notice the twoodworth roaming profile folder created.


Don't log on NIFCS\Twoodworth from her workstation, yet!!!!!!! If you do, NIFCS\twoodworth local profile will be overwritten. Danger! you lose your job.!


Find NIFCS\Twoodworth roaming profile folder, take ownership as administrators, make sure you tick "Replace owner on subcontainers and objects".

Then, you logon NIFCS\twoodworth from her workstation and logoff her. Her local profile will be uploaded to the server.

NTUser.dat file is very important. It keeps all the records of your profile. Don't take it lightly. Don't delete it. Don't create a new one from another computer for roaming profile.