Remote Assistance and Mandatory profiles
Hello all,
I've just implemented mandatory profiles and it seems that Remote Assistance doesn't work anymore. I can confirm that it works with normal profile.
Google told me that it's known problem that many people are facing, however I haven't seen any solution. The workaround with changing the "State" registry key is NOT solution - the profile is no longer mandatory and is not deleted after logoff.
Any ideas how to solve it?
Thanks,
Martin
Better late than never... KB2936674 is a hotfix coming in April 2014, that enables unsolicited Remote Assistance when using mandatory profiles (for Windows Server 2008 R2).
Similar Messages
-
Client SP3 IR4 and Mandatory profile and login script
Anyone have this working on Windows 7 or is this still broken? saw this was supposed to be fixed in SP2 ir3 but cant get it to work
Anyone have ideas?
Thanks!jb001,
It appears that in the past few days you have not received a response to your
posting. That concerns us, and has triggered this automated reply.
Has your problem been resolved? If not, you might try one of the following options:
- Visit http://support.novell.com and search the knowledgebase and/or check all
the other self support options and support programs available.
- You could also try posting your message again. Make sure it is posted in the
correct newsgroup. (http://forums.novell.com)
Be sure to read the forum FAQ about what to expect in the way of responses:
http://forums.novell.com/faq.php
If this is a reply to a duplicate posting, please ignore and accept our apologies
and rest assured we will issue a stern reprimand to our posting bot.
Good luck!
Your Novell Product Support Forums Team
http://forums.novell.com/ -
Unable to take Remote Assistance from SCCM2012R2 Console
Hi,
I am Unable to take Remote Assistance from SCCM2012R2 Console. I am getting below error.Have you configured the Client Settings for Remote Assistance and is the account you are using granted access to perform a remote assistance?
Kent Agerlund | My blogs: blog.coretech.dk/kea and
SCUG.dk/ | Twitter:
@Agerlund | Linkedin: Kent Agerlund |
Mastering ConfigMgr 2012 The Fundamentals -
Windows Remote Assistance work?
Hi,
I collaborate with someone far away. I just bought a Mac and have found to my regret that the screen share function works only with other Leopard users. MSN Messenger for Mac does not have the Remote Assistance and Application sharing functions. Does the Messenger running on a Mac, but inside XP or Vista, have the Remote Assistance or Sharing functions?In the MS Messenger for Mac the Application Sharing and Remote assistance are disabled, so I was hoping before I install XP or Vista on my mac, to find out if it works when running XP or Vista on the Mac. As for why nit, I don;t know. I don;t know why it isn;t on MSN MEssnger for Mac so I was looking for a real world advisor.
-
I have a WRT54G ver 6 and firmware 1.01.0 with port 3389 opened for my IP address, enabled and with no other firewalls. I can not initiate nor accept a Remote Assistance request from another city with either of my laptops. Any ideas?
It seems to me that getting this device to work properly should not be so difficult.Do you think a static IP is necessary? As long as the private IP address has not changed and both ends know what the private IP is there should be no need for a static IP address assigned to the remote host.
-
Disable Active Setup with Mandatory Profile and UEV 2.x??
Hi, I have been doing some research into UEV configuration with the use of mandatory profiles. I'm wondering if Disabling Active setup is something we should do to increase the logon time? if so what issues may I run into if I disable? what
is the process for disabling, is it just delete each registry entry or is there a global setting?Not really an Ue-V question, but here goes..
Active setup is a tricky one. In order to disable active setups you can find out what triggers the active setup to run or not run and incorporate those settings into your mandatory profile. i.e. whatever registry keys the active setup creates
when it runs. If they are present, this should prevent the active setup from running. Results can be mixed depending on what the active setup is doing. Trial and error is required.
Depending on how the mandatory profile is configured, stored, accessed, etc it can greatly reduce login times. If this is for some kind of RDSH environment without persistent profiles I would recommend avoiding any applications with active setup because
you can run into issues during times whenever everyone is logging in. i.e. each morning. There can only be so many msiexec.exe running on each box at any given time, so users get queued up waiting for an opening. I recommend, if possible,
to repackage the applications that currently have an active setup in such a way that will remove the active setup. If that isn't possible, stuffing the whatever information active setup writes into the mandatory profile may work. Good luck. -
Hi Dear,
I have a requirement to configure couple of terminal servers in Windows server 2012.
However we do not want any user to save anything onto their local profiles. Around 200 users will be using this terminal server for their use with multiple applications that will be installed in the server.
Is it possible to configure user mandatory profiles via Group Policy. Really appreciate of someone can provide me the steps preferably in the easy mode. However to test it I have created a test server since I am not that good at registry values would not
do any harm to the environment.
I am using Server 2012 as a test terminal server and active directory is 2008.
Thank You in Advance.
-vikramHi,
for assistance with TS/RDS, the dedicated forum is here:
https://social.technet.microsoft.com/Forums/windowsserver/en-US/home?forum=winserverTS
Further reading for you:
Manage User Profiles for Remote Desktop Services
https://technet.microsoft.com/en-us/library/cc742820.aspx
http://blogs.msdn.com/b/rds/archive/2009/06/02/user-profiles-on-windows-server-2008-r2-remote-desktop-services.aspx
http://blogs.msdn.com/b/rds/archive/2012/11/13/easier-user-data-management-with-user-profile-disks-in-windows-server-2012.aspx
Managing Roaming User Data Deployment Guide
http://go.microsoft.com/fwlink/?LinkId=73760
Don
(Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!) -
Mandatory Profiles - exclude Administrators?
Hi folks,
We're recently changed our Terminal Services profiles from "Citrix Profile Mgmt" (similar to Roaming Profiles but with some enhancements) to Mandatory Profiles. The configuration took place using the GPOs in
Computer Configuration | Policies | Administrative Templates | Windows Components | Remote Desktop Services | Remote Desktop Session Host | Profiles
When we log in with the Domain Administrator we get the same mandatory profile as normal users. Is there a way we can exclude the Administrator account from using the mandatory profile?
Our setup:
Domain Controllers: Win2k8 R2 Enterprise
Terminal Servers: Win2k3 R2 Standard
Thanks in advance!
Rgs
OliYou can set the mandatory path in the users profile tab in their user account in AD Users and Computers raither than group policy. If set per user this would bypass the Administrators - we set ours to
\\servername\sharename\mandatory\ the actual manadatory profile has the .V2 on it for 2008 R2 profiles. If they are logging into Desktops as well, set it in the Remote Desktop profile path
tab instead of the general profile path. -
Remote Assistance missing buttons
Hello,
I'm not sure if this is the correct forum to ask this question. I couldn't find anything related specifically to Remote Assitance. I'm running into a strange issue where the Remote Assistance window is missing buttons. For example, when
launching Remote Assistance with the /offerra switch, the Next and Cancel buttons are just simply gone:
The server I'm launching this on is running Windows Server 2008 R2 with Citrix XenApp 6.5 installed. This issue happens to the published app in Citrix as well as launching it on the server via RDP and via the Console. This was not an issue
until I installed Windows Updates back on 11/9. I removed all of the updates that were installed that day and it still results in the same. I uninstalled/reinstalled the Remote Assistance feature and that has done nothing. I've also tried
multiple accounts and using an account with a brand new profile - in case it was just a strange profile issue.
Any ideas??Hi Luke,
I just had the same issue but only on one server using local profiles... I created a local admin account and it worked under that account. Deleting and recreating my profile on the offending server has resolved the issue, although it was a headache
getting a new profile:
- deleted profile using local admin account (got an error about priviledges held by client)
- manually deleted C:\users folder and profile SID key (and .bak key) from 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList'
- after that logging on gave error 'Profile Service failed' then logged off
- manually created C:\users folder and the SID key again under above location, then I logged on successfully with a new profile and the buttons appear again in RA
There seem to be many people with this problem and several possible resolutions. See
http://forums.citrix.com/thread.jspa?threadID=263507&tstart=0&start=60 for some other options. One says to copy the msra.exe from a Win7 machine, maybe that will work?
Hope something here helps!
Cheers,
Simon -
App-V 5.0 SP2 with Mandatory Profiles
Hi,
We are having some issues with App-V 5.0 SP2 with HFX2 and HFX4 on our Windows 7 x64 Clients
We use mandatory profiles and delete the local profile on logoff,
HFX2 Issue:
The AppData\Local\Microsoft\AppV\Client\VFS\<GUID> is only created once, subsequent logins don't have the folder structure created for the package VFS and all folders have read/write access for the user, when they should follow the base OS folder permissions
We have found that a registry entry is created in HKLM\Software\Microsoft\AppV\MAV\Configuration\Packages\<GUID>\UserConfigEx\<USER-GUID>
if we manually delete this registry key then appv will re-create the VFS folders in local app data
AppV seems to be setting key's saying its created those folders and expects them to be there on the next login, is there a way to tell AppV that we are using mandatory profiles and to re-create the folders?
HFX4 Issue:
Hotfix 4 is a bigger problem in that a registry entry for <USER-GUID> is created in HKLM\SOFTWARE\Microsoft\AppV\Client\Virtualzation\LocalVFSSecuredUser
The first time appv is used for that user, it works, all subsequent times appv packages fail to load unless that registry string is manually deleted.
Is there any way to fix App-V 5 to work with mandatory profiles which are deleted on logoff?
Thanks!Hi Nicke,
The registry key's are located in HKLM, which causes permission problems as our uses are all standard users
the HFX2 issue sort of works, the
UserConfigEx key is created with the logged on user having read/write permissions, so as long as that user successfully runs a logoff script then the key is deleted, if the desktop crashes without running the logoff script and a new user logs in, then they
don't have the rights to delete the sub keys and all future app-v localappdata VFS permissions are broken on that client,
The HFX4 issue registry keys are all write protected from standard users,
I'm not 100% sure these are the only area's which are causing problems (they are just the ones I've found!) and that just deleting the registry entries completely fixes the problem. I didn't go down the path of deleting HKLM keys as a user as it seemed
a bit of a brute force hack to me which I was trying to avoid :)
If I give users rights to delete HKLM\Software\Microsoft\AppV\MAV\Configuration\Packages subkeys
then I think they could break published applications if the <GUID> folders are somehow deleted?
I was actually pretty surprised to find out that App-V 5.0 stores permanent information about user's in the HKLM hive, I would have thought all of this should live in the HKCU hive!
I've not been able to find any documentation on how App-V uses HKLM keys to keep track of processes its already performed on a user and doesn't want to do again,
Thanks! -
Can't open secured documents on windows 7 domain client with mandatory profiles.
While opening certain PDF files we have the problem that the user is presented with a message that he does not have the rights permissions. This happens twice, after that the users gets an empty page with the message the Adobe version might not be up to date. We use Acrobat Pro 10, but this also happens while using Reader 11.0.8. On our windows 2008 terminal services machine this could be fixed by giving the user rights on c:\ to create and remove a file. :O. On windows 7 this doesn't work probably because of UAC. But we've tried every solution to that available on the internet, disabling uac, changing uac options, changing rights on userprofile folders, changing rights on c:\ but to no avail. When using process explorer we can see it wants to create a temp file p328hkl.tmp or something like that on C but it can't and immediattely after is shows the error on screen.
Anyone who also has this problem or solved it? There are no problems with simple self made pdf files/scans but only with certain types of pdf files for which it tries to create a tmp file.
Thanks,
PeterHi Brogers,
Thanks for your reaction. We do have AppData redirection in place. We redirect AppData to a share on our data server which works perfectly fine for all other applications. The weird thing is that Reader/Acrobat try to write to C:\ which to my knowledge should not happen, is this maybe a fallback because it can’t write to a different location? Users have full control on their own roaming AppData but not on their local AppData that is made by windows itself while copying the mandatory default profile to C:\.
I might use the wrong term while saying secured documents. I’m talking about a document created by Raet/Youforce a web application for personal administration. The documents can be opened by other viewers than Acrobat/Reader but then only contain the background and not the text. In Acrobat/Reader they do open normally when Acrobat/Reader can create the .tmp file. Otherwise it will not display the file at all. I would attach such a document to see but since it contains certain info I am not allowed to do so.
I hope we can work out a solution for this.
Met vriendelijke groet,
Peter Gerritsen
Engineer
AndoBurg BV
Voorstraat 31
3931 HB Woudenberg
T 033 479 40 80
F 033 479 40 89
E [email protected]<mailto:[email protected]>
I www.andoburg.com<http://www.andoburg.com/>
Als u niet de geadresseerde van dit bericht bent, verzoeken wij u ons hiervan op de hoogte te brengen en het bericht te verwijderen. AndoBurg BV aanvaardt geen aansprakelijkheid voor schade die voortvloeit uit elektronische verzending van informatie. Aan de inhoud van deze e-mail en eventuele bijlagen kunnen geen rechten worden ontleend, tenzij schriftelijk anders is overeengekomen.
Van: brogers_1
Verzonden: vrijdag 19 september 2014 20:10
Aan: Peter Gerritsen
Onderwerp: Can't open secured documents on windows 7 domain client with mandatory profiles.
Can't open secured documents on windows 7 domain client with mandatory profiles.
created by brogers_1<https://forums.adobe.com/people/brogers_1> in Enterprise Deployment (Acrobat and Reader) - View the full discussion<https://forums.adobe.com/message/6745441#6745441> -
Local Mandatory Profile breaks Metro Apps
I'm not sure whether this is the right section of the forum; tell me if i'm wrong. Also I apologize for my English, I'm Italian.
I want to setup one PC with a "self-resetting" user profile so that every time the user logs out everything he's done is deleted. In Windows XP I used Windows Steady State to achieve something similar.
I tried with software like Reboot Restore RX (freeware alternative to Deep Freeze), but they're not what i need (they reset all changes to the Hard Drive, which means that antiviruses and Windows itself cannot save upgrades).
I followed an howto in order to setup a Mandatory Profile on Win 8.1, because that seemed exactly what I need. My steps:
1. Create a standard user TEST. Log in that user and log out
2. Go to "Advanced System Properties" -> "User Profiles" and copy "default profile" to
C:\Users\MandatoryTEST.V2 allowing "\Everyone" to access it (with "Copy to" button)
3. Open "lusrmgr.msc" and assign C:\Users\MandatoryTEST
as Profile Path for user TEST
4. Log in TEST and start customizing things. Up to this point, everything works. Settings and files are preserved between logins, as expected
5. Rename the file NTUSER.DAT to
NTUSER.MAN in C:\Users\MandatoryTEST.V2 directory. This should "freeze" the profile
Those steps works well until i log into TEST
the second time after "mandatorizing" the profile. Default Metro apps like Weather and News suddenly disappear, and i can't access either Store nor Settings (they crash at launch). Am I doing something wrong? Or maybe there's a better way
to accomplish what I want?
Thanks in advance for your replies.Hi,
In my opinion, whether temp file could use Store APP depends on Default Profile. However, default profile doesn't contains Store APP, such as, weather, finace, Bing Map, etc. If you want to use these Store App, you need to customize the default profile firstly,
make sure these app componments cotained in Default Profile.
To customize Default Profile, you can refer to the contents of the link below for more details:
http://technet.microsoft.com/en-us/library/gg241188(v=ws.10).aspx
Roger Lu
TechNet Community Support -
Hi,
After the update 1 on windows 8.1. All of our domain users get "you cannot access the windows store because you're signed in to this pc using a temporary or guest account......" while opening windows 8.1 store. All my users use mandatory
profiles. Could some one guide me onto:
-how and what changes should I make on my base image of 8.1?
-how/where what changes should I make on the domain in Group policy to make my profiles work?
-I also run sccm 2012 R2 if that makes the things easier I can use it for deploying store apps, but I prefer to make a base windows 8.1 image throw all required apps on it. I would like to make sure that my domain user can open up windows store after
that I can capture this image and deploy.
Need help thanks
Note: Before this update 1 of windows 8.1 things worked great.Thanks Kate Li,
Domain profile is not corrupt. I have checked the registry settings. In my question I am mentioning that I am using mandatory profiles for domain users. Need help.
I am on update 2 now and the same error for domain users with mandatory profiles.
Also error 1001 is generated every time the user tries to open the store(the user with mandatory profile)
Log Name: Application
Source: Windows Error Reporting
Date: 9/30/2014 8:52:17 AM
Event ID: 1001
Task Category: None
Level: Information
Keywords: Classic
User: N/A
Computer: TCO-TTTEST.mydomain.com
Description:
Fault bucket , type 0
Event Name: WWAJSE
Response: Not available
Cab Id: 0
Problem signature:
P1: winstore_1.0.0.0_neutral_neutral_cw5n1h2txyewy
P2: Windows.Store
P3: 3e43
P4: FFFFFFFE
P5: (null)
P6: 0_0
P7:
P8:
P9:
P10:
Attached files:
ErrorInfo.5160.3992.txt
C:\Windows\WinStore\AppXManifest.xml
These files may be available here:
Analysis symbol:
Rechecking for solution: 0
Report Id: 9b46f622-48a0-11e4-bec5-6036dd67e10b
Report Status: 262144
Hashed bucket:
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Windows Error Reporting" />
<EventID Qualifiers="0">1001</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2014-09-30T12:52:17.000000000Z" />
<EventRecordID>366588</EventRecordID>
<Channel>Application</Channel>
<Computer>TCO-TTTEST.mydomain.com</Computer>
<Security />
</System>
<EventData>
<Data>
</Data>
<Data>0</Data>
<Data>WWAJSE</Data>
<Data>Not available</Data>
<Data>0</Data>
<Data>winstore_1.0.0.0_neutral_neutral_cw5n1h2txyewy</Data>
<Data>Windows.Store</Data>
<Data>3e43</Data>
<Data>FFFFFFFE</Data>
<Data>(null)</Data>
<Data>0_0</Data>
<Data>
</Data>
<Data>
</Data>
<Data>
</Data>
<Data>
</Data>
<Data>
ErrorInfo.5160.3992.txt
C:\Windows\WinStore\AppXManifest.xml</Data>
<Data>
</Data>
<Data>
</Data>
<Data>0</Data>
<Data>9b46f622-48a0-11e4-bec5-6036dd67e10b</Data>
<Data>262144</Data>
<Data>
</Data>
</EventData>
</Event>
Thanks
Followed :
http://support2.microsoft.com/kb/2890783 Made a brand new profile. No luck same error. -
Remote assistance from Mac to PC
Hey, my mother occasionally has issues with her PC and asks for my assistance. Before, I just used the Remote Assistance feature in MSN Messenger and fixed the issue using my Dell laptop. Now that I have made the FANTASTIC move to a MacBook, I am looking for a way to give my mother assistance, and it does not seem possible through Microsoft Messenger on Mac.
Is there a way I can remotely assist my mother, on her pc, from my MacBook.
P.S. She is in Iowa and I am in Minnesota, in case that makes a difference in your suggestions. Also, she is running Windows XP and I am running Snow Leopard.
Thanks!I did download that earlier tonight, but I had not used it as I was unsure how to connect to my mothers computer in Iowa. I am not the best when it comes to networking, and this option looked like it would only help if my mothers comp was on the same home network as my own.
How do I connect to her since we are on totally different networks? I am utilizing a shared wireless connection, and she is using a wireless network I set up for her at my parents home. Ideas? -
Hello,
Before to use remote assistance in windows 8.1, i need to configure my nat router freebox.
But remote assistance ( msra.exe ) use a dynamique port and never the same.
How to use a fixed port for remote assistance ini windows 8.1 ?
And why i can't use easy connect ?
i read that the router must implement the PNRP protocol. I think it's a propriatary microsoft's protocol unknow on my router.
ThanksHello,
Very good. It's a big range ( 255 mini from 49152 ) for a single port but if it's the only one possibility...
You are very helpfull ( i don't know if it's a good english but you make me very happy )
Merci beaucoup
Maybe you are looking for
-
Error in SAP standard workflow ddoStart - Start document distribution
Hi all, I'm trying to use the document distribution but i'm failing completely. After doing what i think is the necessary config (setting all relevant tasks to general task should be all), i try to distribute. I create a list, selects people and clic
-
Encoding Problem - can't read UTF-8 file correctly
Windows XP, JDK 7, same with JDK 6 I can't read a UTF-8 file correctly: Content of File (utf-8, thai string): เม็ดเลือดขาว When opened in Editor and copy pasted to JTextField, characters are displayed correctly: String text = jtf.getText(); text.getB
-
Wacky wifi problem. Completely broken. Anyone help? Please?
My macbook(10.5) suddenly dropped my wifi connection last night. I clicked the airport tab in the menu bar and noticed all the available networks (mine and neighbors) are all there, but they are spelled wrong. For instance, my network is called "iRiz
-
Browser Alignment Discrepancies
I've been developing websites with Dreamweaver for about 5 years now and recently purchased an Apple MAC G5 Dual 2. I have Dreamweaver 8.0 which operates much like Dreamweaver MX on the PC like I'm used to. I have encountered frustrating display disc
-
I bought Sony Vaio Flip with Win 8.1. I installed PSE12 & imported 10+ years of photos. After many hours tagging and face recognition, catalog would not back up. Tried to Reconnect - failed due to "corrupt database". Now I cannot reconnect, backu