Click here to get back home

Terminal Services Profiles problems

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Terminal Services Profiles problems Mike Bailey 08-15-2005
Posted by Mike Bailey on August 15, 2005, 5:08 pm
Please log in for more thread options
I'm setting up a few people with rights to access our server via Remote
Desktop. This is on Server 2003, which is also PDC. I don't want
profiles to be stored on the C:\ drive for space considerations, so I
have created a folder on the D: drive for Terminal Services Profiles.
In each users profile, I add the path to this location in the Terminal
Services Profile Tab
ex: \server-name\d$\Terminal Services Profiles\username

Somehow, I've messed up the security on these folders. Now, when one of
the users that is not a member of the Domain Admin group tries to log in
they get a message saying:

---------------
Windows cannot locate the server copy of your roaming profile and is
attempting to log you on with your local profile....possible cause of
this error include...or insufficient security rights.

Detail - Access is denied.
---------------

Here are the permissions on the top level folder:
Administrators: full
Creator Owner: Special- create files/write data create folders
Users: modify, read, execute, write, list folders, special

Before I messed up the security, and I have no idea what I did, if I put
a path in the users TS Profile, a folder with their username would
automatically be create (I think). But now this will not happen - and if
I create the folder, I still get the error above.

Any suggestions???

Thanks,
Mike Bailey


Posted by Steven L Umbach on August 15, 2005, 5:25 pm
Please log in for more thread options
Hi Mike.

I think the problem is that you used d$ in the share path. D$ would be a
hidden administrative share that only administrators can access. If you
create a share for what you want to do just list it in the path such as
\server-name\Terminal assuming terminal would be the name of the
hare. --- Steve


> I'm setting up a few people with rights to access our server via Remote
> Desktop. This is on Server 2003, which is also PDC. I don't want profiles
> to be stored on the C:\ drive for space considerations, so I have created
> a folder on the D: drive for Terminal Services Profiles. In each users
> profile, I add the path to this location in the Terminal Services Profile
> Tab
> ex: \server-name\d$\Terminal Services Profiles\username
>
> Somehow, I've messed up the security on these folders. Now, when one of
> the users that is not a member of the Domain Admin group tries to log in
> they get a message saying:
>
> ---------------
> Windows cannot locate the server copy of your roaming profile and is
> attempting to log you on with your local profile....possible cause of this
> error include...or insufficient security rights.
>
> Detail - Access is denied.
> ---------------
>
> Here are the permissions on the top level folder:
> Administrators: full
> Creator Owner: Special- create files/write data create folders
> Users: modify, read, execute, write, list folders, special
>
> Before I messed up the security, and I have no idea what I did, if I put a
> path in the users TS Profile, a folder with their username would
> automatically be create (I think). But now this will not happen - and if I
> create the folder, I still get the error above.
>
> Any suggestions???
>
> Thanks,
> Mike Bailey




Posted by Steven L Umbach on August 15, 2005, 5:38 pm
Please log in for more thread options
I also found this reference to a registry mod that can change the default
location of user profiles for normal interactive logon. If you want to try
it I suggest that as always for best practice that you make a full backup of
your server first. You may also want to post in a Windows Terminal Server
newsgroup to see if such a registry mod has been successfully used or if
they have other advice. --- Steve

http://windows.about.com/od/tipsarchive/l/bltip212.htm

Hive: HKEY_LOCAL_MACHINE
Key: Software\Microsoft\Windows NT\CurrentVersion\ProfileList
Name: ProfilesDirectory
Data Type: REG_EXPAND_SZ
Value: path

Please be sure to back up your Registry and your current Profiles before
making changes. Also note that this will only take effect for users logging
in after the change to the Registry. You may also have to copy the Default
User profile to the new location.


> Hi Mike.
>
> I think the problem is that you used d$ in the share path. D$ would be a
> hidden administrative share that only administrators can access. If you
> create a share for what you want to do just list it in the path such as
> \server-name\Terminal assuming terminal would be the name of the
> are. --- Steve
>
>
>> I'm setting up a few people with rights to access our server via Remote
>> Desktop. This is on Server 2003, which is also PDC. I don't want
>> profiles to be stored on the C:\ drive for space considerations, so I
>> have created a folder on the D: drive for Terminal Services Profiles. In
>> each users profile, I add the path to this location in the Terminal
>> Services Profile Tab
>> ex: \server-name\d$\Terminal Services Profiles\username
>>
>> Somehow, I've messed up the security on these folders. Now, when one of
>> the users that is not a member of the Domain Admin group tries to log in
>> they get a message saying:
>>
>> ---------------
>> Windows cannot locate the server copy of your roaming profile and is
>> attempting to log you on with your local profile....possible cause of
>> this error include...or insufficient security rights.
>>
>> Detail - Access is denied.
>> ---------------
>>
>> Here are the permissions on the top level folder:
>> Administrators: full
>> Creator Owner: Special- create files/write data create folders
>> Users: modify, read, execute, write, list folders, special
>>
>> Before I messed up the security, and I have no idea what I did, if I put
>> a path in the users TS Profile, a folder with their username would
>> automatically be create (I think). But now this will not happen - and if
>> I create the folder, I still get the error above.
>>
>> Any suggestions???
>>
>> Thanks,
>> Mike Bailey
>
>




Similar ThreadsPosted
Security bug in terminal services? May 4, 2006, 4:02 am
Logon Using Terminal Services GPO August 16, 2007, 2:57 am
How do I configure Terminal Services for 443 access only February 12, 2006, 10:37 am
Deny Logon through Terminal Services Issue August 22, 2006, 12:49 pm
Digital signature, USB tokens and terminal services September 25, 2006, 9:16 am
Terminal services-give a program admin rights January 10, 2006, 4:14 pm
Prevent browsing with UNC paths for Terminal Services users April 5, 2006, 2:05 pm
Deny Right to Local Admin Group to Log On Via Terminal Services? May 24, 2007, 12:28 pm
Terminal Services Security Issue with Cached Credentials October 29, 2007, 12:53 pm
Domain Controller Policy setting "Allow log on through Terminal Services" April 1, 2008, 12:01 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap