Custom NTFS permissions on roaming profiles?



Hello all,

We are managing a large Windows 2003 server environment with Terminal
Servers that store the users' roaming (mandatory) profiles on a file share
on the network. According to
http://technet2.microsoft.com/WindowsServer/en/Library/20b15453-f7c9-4cf0-9131-78924af776551033.mspx,
the default file permissions for a users' roaming profile folder is Full
Control for the user and Local system and nothing else. We have also through
a GPO enabled the "Add the Administrators security group to roaming user
profiles" setting to grant Administrators permissions on the user folders.

So far, so good, but now as the environment grows large, we need our
Terminal Server guys to have permissions on the roaming profiles to be able
to troubleshoot end user problems. We do not want to add the Terminal Server
administrators to the Administrators group on the file servers, but instead
add another group to the ACL of the roaming profile folders.

My question: Is there a way to pre-define which permissions gets set on
newly created roaming profile user folders? If not, what problems could we
run into if we add this extra group to the roaming profile folders
afterwards?

Thanks,

Marcus

--
The views and opinions expressed above are strictly
those of the author(s). The content of this message has
not been reviewed nor approved by any entity whatsoever.



.



Relevant Pages

  • Re: Roaming profiles in Windows XP
    ... You don't get roaming profiles without a Microsoft server. ... with message store across a network. ... pointed the profile path on the clients machine ...
    (microsoft.public.windowsxp.security_admin)
  • Re: changes not saving
    ... in the user profile, then logoff again. ... times on the network share where the roaming TS profiles are stored ... MCSE, CCEA, Microsoft MVP - Terminal Server ... caching for offline files is disabled as noted in the kb ...
    (microsoft.public.windows.terminal_services)
  • Re: roaming profile error message
    ... profile on the server? ... user at the Branch Office to the User Shared Roaming Directory at the Main ... >>> Our main office has windows 2003 server. ...
    (microsoft.public.exchange.admin)
  • Roaming profiles in Windows XP
    ... roaming profiles on a workgroup of Windows XP ... Professional workstations (no server). ... pointed the profile path on the clients machine ... being 'Roaming' too on the client computers? ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Cannot get roaming profiles to work
    ... Have you checked the permissions on the folders your want the roaming ... > so as administrator on the SBS server. ... > profile to the server after logon. ... No checks are made for the correct permissions if the profile folder ...
    (microsoft.public.windows.server.sbs)

Loading