Solved

Roaming Profile Folders Do Not Allow Administrative Access  *Administrator needs access to files after the fact *

Posted on 2004-04-01
12
734 Views
Last Modified: 2010-05-18
Okay I understand Microsoft’s article http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B222043  states that you can not apply the GPO after the profile is made.  I came into this job after this was setup (incorrectly).  But, I need to be able to view the files in the roaming profiles now. I want my users to still be able to access their profiles also.  What I need is a way to add the administrator to the security settings so that I am able to view the files while still having the user access the profile.  Taking ownership removes the user access rights to the profile. Any ideas?  
0
Comment
Question by:MDavisTX
  • 4
  • 3
  • 3
  • +1
12 Comments
 
LVL 3

Assisted Solution

by:infradawn
infradawn earned 100 total points
ID: 10732937
The ACLs on the default profile are: USER - FULL CONTROL and SYSTEM - FULL CONTROL. Maintenance is straightforward if you use the SYSTEM account to do it. The easiest way to delete profiles using the SYSTEM account is to schedule a cmd.exe /k job using AT (or SOON). This creates a DOS window in the SYSTEM account context and profiles can be deleted from here (so no need to take ownership).

See:

http://www.experts-exchange.com/Operating_Systems/Win2000/Q_20914408.html

for a discussion.


iD
0
 
LVL 3

Expert Comment

by:infradawn
ID: 10732975
Oh yeah, missed saying that the technique is also useful for viewing and otherwise maintaining the profiles!

iD
0
 

Author Comment

by:MDavisTX
ID: 10733763
Okay i kind of understand what you are saying. Can explain in more detail as to how I use the SYSTEM account?  I am sorry but I am fairly new to Windows 2000 Server.
0
 
LVL 7

Assisted Solution

by:4auHuk
4auHuk earned 100 total points
ID: 10734601
>Taking ownership removes the user access rights to the profile
No, it's not. Take ownership does not change ACL.

>Can explain in more detail as to how I use the SYSTEM account?
>>The easiest way to delete profiles using the SYSTEM account is to schedule a cmd.exe /k job using AT

at.exe is built-in command line scheduler. Tasks scheduled using AT always start under Local System account. So all you need is to open command prompt and use AT with following syntax:
at 13:30 /interactive "cmd /k"
where 13:30 is in near future. At this time command prompt window will appear. It will run under Local System account.
0
 
LVL 83

Accepted Solution

by:
oBdA earned 300 total points
ID: 10734763
Once you have the command window open, use cacls to add the administrators group to the ACL:
cacls YourHomeRoot /T /E /G Administrators:f
will add the group Administrators to YourHomeRoot and all files and folders below (/T), leaving the existing ACEs as they are.
Do not miss the /E ("edit", instead of replacing the ACL) switch, or you'll have to re-add your users and the system account ...
0
 

Author Comment

by:MDavisTX
ID: 10741418
oBdA,

Okay i ahve looked into the cacls command.  It looks promising. My HomeRoot is D:\Profiles$\  do you think it will have a problem with the $ ?
0
Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

 
LVL 83

Expert Comment

by:oBdA
ID: 10741711
There should be no problem; a $ can be a regular chanracter in a file or folder name.
If you feel unsecure about it, simply create a test folder using a similar folder and permissions structure and start with this one.
0
 

Author Comment

by:MDavisTX
ID: 10742277
4auHuk and oBdA

Okay i am trying out the at command but i am getting an error on the scheduling of it

I am running a cmd prompt and have put in the command:

at 10:45 /interactive "cmd /k"

the time passes and no new cmd opens and if i look at the AT schedule it states that it as an error in it
Status ID   Day                     Time          Command Line
---------------------------------------------------------------
Error   2   Tomorrow                10:45 AM      cmd/k

i assume the tomorrow statement means it will try again tomorrow.

I have try many ways

at 10:45 /interactive "cmd/k"
at 10:45 /interactive cmd / k
and so on
0
 
LVL 83

Expert Comment

by:oBdA
ID: 10743137
Try to lose the "/k" completely;
at <Your:Time+2min> /interactive cmd
works fine for me.
0
 
LVL 7

Expert Comment

by:4auHuk
ID: 10743919
Yeah, /k is extra key since cmd starts with is by default :)
"Tomorrow" means that time in "at 10:45 /interactive "cmd /k"" command was in the past so at assumes you wish to start this task tomorrow. Anyway, oBdA mentioned all this already :)
0
 

Author Comment

by:MDavisTX
ID: 10743971
Thanks, all three of you got me the answer!!
0
 
LVL 3

Expert Comment

by:infradawn
ID: 10752553
:)
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Are you unable to connect or configure Hotmail email account in Microsoft Outlook 2010, 2007? Or Outlook.com emails are not downloading to Outlook? Lets’ see the problem and resolve Outlook Connector error syncing folder hierarchy (0x8004102A).
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now