Local forest roaming profiles with remote forest users within RDS?

We have been using RDS for some time now. New users get a new profile from (*1)"\\domain_1\netlogon\Default User.v2" when they first logon to a RDS session host. Ones that is done, the profile is becomes roaming profile that is stored on (*2) "\\some_serverx_in_domain_1\profiles$\%username%".
(Note, this last setting can be set in 4 different places. We used a GPO and used the Remote Desktop Services section to set it) 
So far, no rocket science. Now...
Recently we've been asked to allow user accounts from another (trusted) forest (domain_2) to our RDS environment. These users are able to logon to our RDS environment but they do not get a fresh profile from our (*1) default profile location. Instead, they
get a default profile from the RDS session host and this new profile does not become roaming so it is not saved to our (*2) location. How can we force the foreign accounts to get a roaming profile within domain_1 without having to change anything outside our
administrative border?  
Note: Their logon servers do not have a "Default User.v2" in their netlogon and their roaming profile settings are set in the AD properties for the user accounts. The roaming profiles they use are pre-2008 and thus unusable for our 2008-R2 RDS environment.
We are not looking for cross-forest roaming profile functionality. We just want foreign accounts to use our roaming profile setup. Please Help! 

Hi,
Thanks for your post.
Make sure the trusted forest user have permission to access the Default User profile. In addition, ensure the following policy was enabled:
Computer Configuration\Administrative Templates\System\Group Policy\Allow Cross-Forest User Policy and Roaming User Profiles
Allows User based policy processing, Roaming User Profiles and User Object logon scripts for cross forest interactive logons. This setting affects all user accounts interactively logging on to a computer in a different forest when a Cross Forest or 2-Way
Forest trust exists.
How to troubleshoot Group Policy object processing failures that occur across multiple forests
http://support.microsoft.com/kb/910206
Best Regards,
Aiden
TechNet Subscriber Support
If you are
TechNet Subscription
user and have any feedback on our support quality, please send your feedback
here.
Aiden Cao
TechNet Community Support

Similar Messages

  • Local and Roaming profiles not being created

    Hello all,
    I'm in need of help and I wondered if there was anyone out there with some suggestions.
    The problem is that one of our sites has Netware 5 and Zfd3.2 and there are no longer any roaming profiles or local profiles being created. Volatile user is not used. Roaming profiles go to the users home directory. All file rights are fine. DLU is still working. Novell client on W2K workstations is 4.90. All other sites appear to be OK.
    I suspected that the user policy was at fault and so created a test user package and associated a test user to it = same result.
    I have checked from top to bottom and compared all settings to other sites and can see no difference or anything unusual. I've been working on this for 2 days now and I'm going grey and bald.
    Any suggestions anyone?
    I'll buy a pint for anyone with the answer - LOL.
    Thanks in advance
    Alan Graham
    email: [email protected]

    elvisgraham,
    It appears that in the past few days you have not received a response to your
    posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Visit http://support.novell.com and search the knowledgebase and/or check all
    the other self support options and support programs available.
    - You could also try posting your message again. Make sure it is posted in the
    correct newsgroup. (http://forums.novell.com)
    Be sure to read the forum FAQ about what to expect in the way of responses:
    http://forums.novell.com/faq.php
    If this is a reply to a duplicate posting, please ignore and accept our apologies
    and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://support.novell.com/forums/

  • App-v 5.0 sp3 Publish application icons/ shourtcut missed on 2nd time logon on terminal server 2012 r2 with roaming profile with folder redirection

    1. I updated app-v 5.0 sp3 environment on 2012 R2. Roaming profile users with folder redirection logon fine at first time applications icons available but at 2nd logon applicaitons icons are missed while packages are available. we are using existing
    roaming profiles with folder redirection which are running in current environment through APP-V 4.6 2008 R2. Please suggest work around to resolve this issue.
    2. TS Nodes of 2008 R2 with App-v 4.6 running fine on Microsoft 2012 private cloud but we are facing performance issue (stuck, slow logon, slow performance etc) when we are moving in new 2012 R2 private cloud. SAP, SCSM and other sevices are running
    fine, please provide solution.
    Thanks

    1.) What are you doing with the App-V Icon path? e.g. %LOCALAPPDATA%\Microsoft\AppV\Client\Integration\<GUID>\Root\AppVClientUX.exe.0.ico ?
    I guess you could workaround it with deploying the icons to a central location and then pointing to the icon out on a central share. Or put the icons in a machine location...I haven't had this issue but that's just off the top of my head.
    2.) I have not used App-V 4.6 in an environment like yours BUT would pre-caching the applications be possible? Any chance you'll be moving those apps into App-V 5.0 soon?
    PLEASE MARK ANY ANSWERS TO HELP OTHERS Blog:
    rorymon.com Twitter: @Rorymon

  • Local and roaming profiles in Samba

    The logon path setting in my smb.conf is enabled and it works fine, but I do not want to use roaming profiles for all users.
    So, and according to the documentation I have read, I use the pdbedit command to set the profile path for an specific user.
    Theoretically, the command "pdbedit -u <username> -p=" should set the profile path to a null string, but and error saying that the value is invalid is shown.
    How can I use both kind of profiles in my server?
    Thanks in advance.

    elvisgraham,
    It appears that in the past few days you have not received a response to your
    posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Visit http://support.novell.com and search the knowledgebase and/or check all
    the other self support options and support programs available.
    - You could also try posting your message again. Make sure it is posted in the
    correct newsgroup. (http://forums.novell.com)
    Be sure to read the forum FAQ about what to expect in the way of responses:
    http://forums.novell.com/faq.php
    If this is a reply to a duplicate posting, please ignore and accept our apologies
    and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://support.novell.com/forums/

  • Can't access my user profile with the supplied user information from Oracle

    I can't access my user account at oracle.com with the supplied user name and password supplied by oracle email.
    user = [email protected]

    I have deleted all cookies and files, can you please give me some feedback asap. I am registered on an Oracle event that I need to be able to unregister but I can't do it since I can't access www.oracle.com.

  • Tiger Login Freezing, Local and Roaming Profiles

    I'm having problems with the login screen. Both server and emac are using the newest 10.4.4 updates and users regardless of logging in to local accounts or accounts on the server are freezing after pressing the "Login" button on the login screen.
    generally speaking the user can login at least once per restart. the problem tends to occur if users logout and then attempt to login another user.
    wondering if anyone has seen this problem
    it only seems to happen with emacs (different gens) running 10.4
    imacs and other machines running the same system/image to not appear to suffer the problem.

    update:
    even updating to 10.4.6 which has become available since the problem first came about there have been no less instances of this happening.
    any help would be great.

  • How I can disable Firefox from browsing Local drives of servers for remote desktop users in Windows Server 2008 R2 SP1??

    Hi ..
    Recently I came across a security hazard in firefox. it displays C and D rives content when "C:\" or "D:\" is typed in browser address bar. is there any workaround for restricting domain users to restrict this on firefox 12 ??
    Thanks

    Hiya,
    It could sound like that one indeed. There are a few options to go for, however it should be fairly easy to find out :)
    Create a test GPO and apply to a limited amount of users. GPUpdate and verify that the GPO has been applied using rsop.msc
    Then open the application to test and see if it has the desired effect. You might need to change more than one setting, depending on the application and desired behavior.

  • Why is my contact list showing Facebook profiles of people whose number I don't have in my contacts? Isn't the "contact list" supposed to only identify and match facebook profiles with contact phone numbers within my iphone?

    When I went into the Facebook app on my iPhone 4S, I tried finding friends through my contact list. I thought only contacts with cellphone numbers matching a Facebook profile would appear to add as a friend. What's being populated are friends of my friends. Why is this happening? A friend of a friend isn't my contact. Shouldn't a true contact have a phone number in my contact list when attempting to match contact to Facebook profile or did things change with iOS 7.0.3??

    Many mail clients reject images, JavaScript and embedded CSS styles.  For best results use plain text near the top to communicate your message and give a link to the actual web page on your server.
    For mail clients that do have limited support for HTML, use uncomplicated tables and inline CSS rules (inside the body tag).  
    All that meta data description is a red flag to spam filters.  You shouldn't be using meta description or keywords in e-mails.
    The article below has some good tips & resources for reliable e-mail templates you could use:
    http://alt-web.com/Articles/HTML-Emails.shtml
    Nancy O.

  • Windows 2012 RDP "resets" user settings while using Roaming Profiles

    Last month we installed a RDP environment running a Windows 2012 DC and 2 Windows 2012 RDP servers. The RDP servers are running in a pool.
    For the rest it's nothing fancy.
    The problem is that user-settings are reset, most likely during logon. This only occurs when we use Roaming Profiles.
    - We create a new user, in a container with no GPO's attached.
    - This user gets a RP while logging on, no errors, at logoff the RP is written to it's correct folder.
    - Logging on again. Now for example I make Chrome standard browser and change the program which opens JPG files.
    - Logging off
    - I check the NTUSER.DAT in the RP folder and the changes I made can be found in the file. So it has been saved to the NTUSER.DAT.
    - Now I login again and check the settings I made. IE is standard browser again and the JPG setting is also back to standard.
    - Logging off
    - Checking the NTUSER.DAT in the RP folder and yes, everything is back to default.
    Now the funny part is, when I create a user with a local profile, everything is working properly. Settings been saved.
    It doesn't make a different what kind of user it is. Domain User, Domain Admin. They all have the same problems when using RP's.
    No error messages in the Event Viewer.
    I'm clearly unable to solve this problem. Hoping someone can help me on this one.
    What makes the settings reset at logon while using Roaming Profiles?
    Thanks!

    Hi,
    Thank you for posting in Windows Server Forum.
    Have you enable Cache copies option of roaming profiles?
    This issue might occurs because the User Profile service does not load the terminal server roaming profile correctly after the user account password is reset.
    When the Delete cache copies of roaming profiles Group Policy setting is enabled, and when a user is prompted to change the user account password, the User Profile service loads a local temporary user profile. The User Profile service loads this user profile
    to perform the password reset operation. However, the profile changes to a combination of the local temporary profile and of the roaming profile after the user password is reset. Therefore, the terminal server roaming profile is not loaded correctly.
    In addition, please try to delete the SID of the user from registry key and check the result. You can follow the below path.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
    More information:
    You receive a "The User Profile Service failed the logon” error message
    http://support.microsoft.com/kb/947215/en-us
    Also check “User Profiles on Windows Server 2008 R2 Remote Desktop Services” article.
    Hope it helps!
    Thanks.
    Dharmesh Solanki

  • Impact on roaming profile accounts if we Change User logon Name to Employee Number format in Active Directory for all User accounts

    I want to understand if we change User logon Name to Employee Number format in Active Directory for all User accounts, then what would be the impact on existing profile. Whether we need to change it manualy or it will connect to same profiles in terminal
    session.
    As i observed it create new profile after logon name changed to employee number where existing users profile settings get fails to load and prompt for new settings (such as outlook reconfiguration, share drive mapping etc.).
    Kindly let me know the proper process to overcome with this, how to connect same existing roaming profile with employee number format change.

    Hi,
    What if we change the user name of user account, will it have impact on roaming profiles.
    Yes, it will affect roaming profiles. Please rename the roaming profile folder as the new user account name, in addition, change the profile path in ADUC.
    Here is an related article below for you:
    How to Rename a Windows 7 User Account and Related Profile Folder
    http://social.technet.microsoft.com/wiki/contents/articles/19834.how-to-rename-a-windows-7-user-account-and-related-profile-folder.aspx
    Best Regards,
    Amy

  • Roaming Profiles: Duplicate folders for each user

    I'm having an issue where each user has 2 roaming profile folders.
    In /users$/ share, i will see:
    /users$/username/
    /users$/username.V2/
    Makes sense, except that inside the /users$/username folder, there is another .V2:
    /users$/username/
    /users$/username/.V2/
    /users$/username.V2/
    Why is the user ending up with 2 (duplicate) V2 folders, one in the root of the profile share, and one inside their folder? 
    This topic first appeared in the Spiceworks Community

    Hello,
    1. this isn't the case by default. It should work the same as with Windows Server 2003 before.
    2. this is expected, even using the same names this is a complete NEW domain what you have built. The SID(Security identifier) is complete different from the old one, that is the reason you have a new profile on the clients.
    Again 1. Please post an unedited ipconfig /all from the DC/DNS server and a client so we can control some basic settings that may run into the problems you have to join machines to the domain.
    To keep everything as it was used on the old DC the following way would be the one to go.
    http://blogs.msmvps.com/mweber/2012/07/30/upgrading-an-active-directory-domain-from-windows-server-2003-or-windows-server-2003-r2-to-windows-server-2012/
    Best regards
    Meinolf Weber
    MVP, MCP, MCTS
    Microsoft MVP - Directory Services
    My Blog: http://blogs.msmvps.com/MWeber
    Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
    Twitter:  
    Thank you Meinolf, for responding to my direct concerns and providing me the link for further directions to properly record the old server data. I will try to post the DC/DNS server and a client workstation IP details Monday, when I am back in the office.
    Thank you again
    Mike

  • Roaming profiles does't work with ZCM 10.3.3

    Hi,
    We have Zenworks Configuration management 10.3.3. Fully patched. We have also latest zenworks agents 10.3.3.44426.
    Our roaming profiles does not work any more after we patched zenworks agents.
    Now our existing Roaming Profiles do not update any more. No matter where profiles are stored (linux, netware or windows).
    We have DLU Policy and Roaming Profile Policy. If I delete the user account and its
    profile on the client, the account will be recreated by DLU-Policy and
    the Roaming Profile gets copied to the server once. After that no changes will be synced.
    It looks it has something with Novell client. If you don't have Novell Client on workstation, everything works fine.
    I try also simulate this problem in test environment. Same problems.
    I am now asking Novell. How it is possible that patch for this is not available ? It looks users has this problems more than half year.
    Are we the only one on this world who are using roaming profiles with Zenworks ?
    Any ideas ?
    Roman

    I knew, I am the only one on this world who are using roaming profiles with Novell client.
    But that is only one of a tousands bugs with Novell Zenworks.
    And novell support ? They need at least two weeks or more to setup one zenworks server and one XP workstation with novell client and test this.
    They are now somewhere in the middle of installing windows XP workstation.
    Roman
    >>> Automatic Reply<[email protected]> 20.9.2011 19:17 >>>
    Roman,
    It appears that in the past few days you have not received a response to your
    posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Visit http://support.novell.com and search the knowledgebase and/or check all
    the other self support options and support programs available.
    - You could also try posting your message again. Make sure it is posted in the
    correct newsgroup. (http://forums.novell.com)
    Be sure to read the forum FAQ about what to expect in the way of responses:
    http://forums.novell.com/faq.php
    If this is a reply to a duplicate posting, please ignore and accept our apologies
    and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://forums.novell.com/

  • Problems with remote control and user accounts - error 1759?

    We're running:
    -XP Pro SP2 clients with Zen SP1 IR3a agent, 4.91 SP2 Netware client.
    -We are NOT running Middle Tier.
    -Novell servers are running Netware 6.5 SP7, E-directory 8.7.3.10b or 8.8.
    -Zen server is also SP1 IR3a.
    We have no problem using remote control on workstation objects. We are having intermittent issues with remote controlling user objects. When the issue occurs, we receive the following error, "Error 1759: The selected user is not logged in on any workstations" even though the user is in fact logged in. After some more research, it appears that the "networkAddress" attribute of the user object is blank so we feel that this is the root cause. My question is what would cause the networkAddress attribute to randomly not update? For instance we had a user (verified his login) who we could not remote via the user object (workstation object worked). We checked his networkAddress attribute and found that it was empty. User rebooted and logged in again and his networkAddress attribute populated, and then we could remote control him via the user object. Now this isn't always the case after a reboot. There doesn't appear to be any pattern to when the networkAddress attribute does or does not update. In fact, this particular user has a laptop so he boots it up fresh every morning yet he was not showing a network address when he logged in initially today.
    We've followed the troubleshooting steps in Novell Documentation without any success. Is there anything else that we might be missing, especially with respect to getting the networkAddress attribute to update? We ran a DSreport on that attribute and found about 500 out of a total of 1500 users had no networkAddress. Some of those are sure to be legitimate but that number is much too high for the number of people that should be in the office.
    I've read some older threads on the subject but none of them really provide a firm solution. Also most of the older threads reference Middle Tier which we are not using.
    Thanks in advance.

    > 4.91 SP2 Netware client.
    You could try this TID:
    "A user will no longer have an entry in their "Network Address" attribute
    even though they are logged into the eDirectory Tree."
    http://www.novell.com/support/viewCo...1262&sliceId=1
    "Resolution"
    "This was fixed in the 4.91 SP3 client. NWFS.SYS was modified so that it
    will check the monitor connection on a reconnect and if it is not connected
    close the connection and try and get a new monitor connection to the tree.
    Prior to the 4.91 SP3 client, the solution is to have the user login again
    so that it issues the NDS Finish Login request again that will populate
    Network Address again."
    Regards
    Rolf Lidvall
    Swedish Radio (Ltd)

  • Roaming Profiles on NSS

    I do not use DLU, as my users authenticate against synchronized AD
    Can Roaming Profile be assigned & how to configure (with user home
    directories/profile etc) being on NSS volume
    Seb

    No, that is not correct.
    Roaming Profiles work fine with DLU and Windows 7 and NSS.
    On 6/18/2013 4:56 PM, HarryBoyee wrote:
    >
    > Hi Craig and Shaun,
    >
    > So just to clarify, if we are running Windows 7 (no-AD) with DLU and
    > Roaming Profiles, we won't be able to "roam" because of Windows 7 and
    > DLU? We would only be able to setup roaming profiles for Windows 7 if
    > we had users login to an AD domain, correct? Most of our users have
    > their 1 computer with a few exceptions but those exceptions are where we
    > see issues with temp and incomplete profiles. Is there any way around
    > this? If not, what I see happening is we put them on a domain and then
    > we no longer need ZENworks for dlu, roaming profiles, and group policies
    > since they are in a domain. We would start to think about why we would
    > need ZENworks and possibly look at alternatives out there for remote
    > management, application deployment, patching, full disk encryption, etc.
    > For now we are looking at no longer using roaming profiles and just
    > have DLU create a local account and maybe redirect the profile folders.
    >
    > Harry
    >
    >
    > craig_wilson;2263670 Wrote:
    >> You may still have Roaming Profiles on NSS Volumes, but you would need
    >> to configure this via your AD Setup, not ZCM Setup.
    >>
    >> This may require configuring some type of Windows Emulation on your
    >> server hosting the NSS Volumes to allow you to configure it through AD
    >> if using Windows 7.
    >>
    >> On 5/14/2013 2:06 PM, spgsitsupport wrote:
    >>>
    >>> craig_wilson;2263322 Wrote:
    >>>> None of this applies to you.
    >>>>
    >>>> #1 - ZCM Does not support Roaming Profiles with an AD Logon with
    >>>> Windows
    >>>> 7. (XP is still fine, but as you move to Windows 7 you will neee
    >> to
    >>>> move to AD Roaming Policies.)
    >>>>
    >>>
    >>> But that also means that I can NOT have Roaming Profiles on NSS
    >> volume
    >>> any more, correct?
    >>>
    >>> Seb
    >>>
    >>>
    >>
    >>
    >> --
    >> Craig Wilson - MCNE, MCSE, CCNA
    >> Novell Knowledge Partner
    >>
    >> Novell does not officially monitor these forums.
    >>
    >> Suggestions/Opinions/Statements made by me are solely my own.
    >> These thoughts may not be shared by either Novell or any rational
    >> human.
    >
    >
    Craig Wilson - MCNE, MCSE, CCNA
    Novell Knowledge Partner
    Novell does not officially monitor these forums.
    Suggestions/Opinions/Statements made by me are solely my own.
    These thoughts may not be shared by either Novell or any rational human.

  • How to change path of Users Terminal Services Profile for multiple AD users on server 2003?

    Hello experts. I am working on a file server migration. All data has been migrated, I am currently working on redirecting users to the new file server. I
    am able to select multiple users at once in ADUC -> right-click -> properties -> profile and here I can change the home folder and roaming profile path for each all users to point towards the new file server. 
    The issue I have run in to is that we have roaming profiles for terminal services users. So, there are hundreds of users that have their terminal services profile
    configured in AD -> Right-click user (one at a time) -> properties -> terminal services profile. Here, the profile path is configured for each user as \\OLDserver\Profiles\%username%
    and I need to change it to \\NEWserver\profiles\%username%. 
    I know that you can configure this path via group policy, I set up a GPO; Computer / Administrative Templates / Windows Components / Terminal Services / “Set Path
    for TS Roaming Profiles” as \\NEWserver\profiles and applied this GPO to an OU containing the TS servers.
    The problem is, the GPO is not working... When I log in to the TS and add a document to My Documents, it is still saving under \\OLDserver\profiles\Username.
    So, the settings in AD are trumping the GPO I believe. What is the best way to accomplish my goal? Thanks in advance!

    > to change it to \\NEWserver\profiles\%username%.
    That is "profile" in opposite to...
    > add a document to My Documents, it is still saving under
    > \\OLDserver\profiles\Username.
    ...this one which is Folder Redirection and has NOTHING to do with
    server based profiles.
    > So, the settings in AD are trumping the GPO I believe.
    No, it isn't. When you do not enable FR and you access "Documents", you
    will never see an UNC path but the local c:\users\xyz\documents folder.
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

Maybe you are looking for