Computer-mandatory profiles stored on server

Posted on 2006-04-12
Last Modified: 2010-04-13
I have a single 2K domain with 2K and XPpro workstations.

Some of our workstations are shared by several users.  For these particular workstations ONLY, I want there to be a profile that is:
  1) specific and unique to that workstation
  2) comes up identically for all users that log on to that particular computer
  3) is stored on the server, for easier admin access & backup.

Setting up a profile locally under All Users or Default User has a couple of shortcomings:  2) is not satisfied because the users' individual desktop icons, etc., are appended to that of All Users, and 3) is not satisfied.

Roaming profiles satisfy 3) but not 1) or 2).

What I want is like a mandatory profile, but associated with *computers* not *users*.
Question by:dv440
    LVL 48

    Accepted Solution

    Hi dv440,

    there is no such thing as a "mandatory computer profile" you have roaming user profiles and thats it, you can create a default account on the machine that  is setup as you like and copy the profile to the default user, the settings will take effect the first time the user logs in and then will copy to their profile store on the server, but this will only work once and any mods they make will copy to their profile

    you need to look at creating a stable profile and then locking down changes

    LVL 5

    Expert Comment

    Jay Jay is right.

    The closest you can get is a seperate user account for each machine and make it a mandatory roaming user profile (to prevent permanent changes), this satisfies 1,2 and 3 but adds the caveat that the user isn't using their own ID to log into those workstations.
    LVL 4

    Assisted Solution

    Hi dv440

    I agree with Jay Jay, but there is another was to overcome this hurdle. While creating group policies microsoft also thought of a similar scenario, in which users might have to user kiosk systems or terminal servers, but the administrators might not want them to be able to customize there profile on these computers. Therefore, Microsoft created a concept of Loopback processing mode of group policies. You just need to put all the shared systems in a seaprate OU & apply a new group policy with loopback processing mode enabled on it.

    For further information regarding loopback policies, please refer :

    Feel free to post any suggestions or queries.

    LVL 1

    Author Comment

    I should add that I'm in healthcare, therefore HIPAA applies, which discourages shared logins.  So I need to add a 4th objective:
      4) users should log in with their individual domain username/password

    I already know there is no simple way to this, from the book learnin' I did to get a MCSE-Security.  

    I would consider third-party solutions, scripts, etc.

    Thanks for the helpful replies so far, I will look into them.  
    LVL 1

    Author Comment

      5) It's okay if users add desktop icons, wallpapers, etc. to the profile once it is set up.  

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    Suggested Solutions

    NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
    Synchronize a new Active Directory domain with an existing Office 365 tenant
    Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
    Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

    745 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now