?
Solved

Windows 2003 Citrix Domain Remote Login Profile issue (new Domain)

Posted on 2007-03-17
3
Medium Priority
?
230 Views
Last Modified: 2013-11-21
I have a Windows 2003 Domain, with multiple Windows 2003 Terminal Servers with Citrix Presentation Server 4.0 installed.  This is a new Domain and new hardware/windows install.  When my clients are logging into my ASP in the new domain they are getting the following:

"Windows did not load your roaming profile and is attempting to log you on with your local profile.  Changes to the profile will not be copied to the server when you log off.  Windows did not load your profile because a server copy of the profile already exists that does not have..." (cuts off there)

and is followed immediately when clicking on OK with:

"Windows cannot find the local profile and is logging you on with a temporary profile.  Changes you make to this profile will be lost when you log off."  

However the profiles are roaming profiles and are set up through Active Directory in this fashion:  

\\Asp-dc\profiles\companyname\%username%

Share on the profiles directory is set to the master access group (ASP User) is set to full control.
Security for the ASP user group is also set to full control under the security tab.  

However when a user logs in, the profile folder is created, but not with the access needed, and gives the error message above.  If I take ownership of the profile directory, then the user will work till they log off, and upon logging back in the same thing happens over again.  

NOTE:  only session information is stored in these profiles so they can be blown away without consiquence.  

Things I tried:
I have also set the everyone to full control to see if I could get around this and it does not work.

Need help in resolving this situation.  Any other information needed will be supplied (screenshots available if wanted).
0
Comment
Question by:Telam
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 37

Accepted Solution

by:
Carl Webster earned 750 total points
ID: 18741963
This is not exactly what you are looking for:
Citrix Profile Best Practices:
http://support.citrix.com/article/CTX110351
You may also want to look at
http://www.msterminalservices.org/articles/Managing-Terminal-Services-Group-Policy.html

When a user logs in, who was granted access to the profile and what rights were they given?
Should be the user, SYSTEM and if set in the GPO, Administrators.


Webster
0
 
LVL 13

Assisted Solution

by:Kini pradeep
Kini pradeep earned 750 total points
ID: 18743636
you could enable the userenv and check the log file. enable it on the TS and login as the user who has a profile problem.
http://support.microsoft.com/kb/221833

if its a ownershipissue then this policy might help:
Computer Configuration / Administrative Templates / System / User Profiles " Do Not Check for user ownership of Roaming Profile Folders "
0
 

Author Comment

by:Telam
ID: 18747463
I am still testing out the solutions that the above have given.  I should know by the end of the day whether or not this has corrected the solution for me.  

Here is an article from MS that I found:  

http://support.microsoft.com/kb/327259/

Will let you know the results soon!

Ted
0

Featured Post

Get real performance insights from real users

Key features:
- Total Pages Views and Load times
- Top Pages Viewed and Load Times
- Real Time Site Page Build Performance
- Users’ Browser and Platform Performance
- Geographic User Breakdown
- And more

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

My previous article  (http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_Server_2008/A_4466-A-beginners-guide-to-installing-SCCM2007-on-Windows-2008-R2-Server.html)detailed one possible method to get SCCM 2007 installed an…
Know what services you can and cannot, should and should not combine on your server.
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses
Course of the Month10 days, 20 hours left to enroll

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question