We help IT Professionals succeed at work.

We've partnered with Certified Experts, Carl Webster and Richard Faulkner, to bring you two Citrix podcasts. Learn about 2020 trends and get answers to your biggest Citrix questions!Listen Now

x

Local cached profile security

meilec
meilec asked
on
Medium Priority
291 Views
Last Modified: 2012-05-05
Hi,

Hopefully someone can help me with this question (its probably something simple!)

All users on our Windows 2003 domain are using roaming profiles. When they logon to a machine a local cached copy of the profile is created. This is fine as we have some remote users and it does help speed things up in regards to logging on.

The problem is that when that local profile folder is created under C:\Documents and Settings\username it is accessible to anyone else who logs in to the system afterwards! I don’t remember this happening on our 2000 domain. As mentioned I don’t want the folder to be deleted I just want it to be locked to all other users.

Thanks in advance.
Comment
Watch Question

CERTIFIED EXPERT
Top Expert 2005
Commented:
It should not be accessible to anyone other than the Administrators Group (local) and the user.

Check the security on the profile folder.

If your user's have local Admin or Power User rights (if specifically added) then they can access the profiles.

Also, check "Documents and Settings" folder to make sure it's not inheriting permissions from the parent and that each subfolder for each profile is also not inheriting.

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts

Commented:
I agree it sounds like the domain users or all local users have been added to the local administrators group.  By default only the domain admin account is added to the local admin group.
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.