?
Solved

Group Policy partly applied

Posted on 2009-07-08
20
Medium Priority
?
302 Views
Last Modified: 2012-05-07
Hello,
I recently created a new group policy object to exclude some folders out of the users' profile. I created the policy so it applies to User's Configuration and initially defined the values of folders to be excluded as follows:
"My Documents";Cookies;"Application Data\Sun";temp
Then Cookies and temp were excluded but not the others. Going through my users' profiles I noticed that the "My Documents" folder inside each profile was named "USERNAME's Documents" (for example, mikew's Documents) so I changed the values of the folders in the policy to the following:
"%USERNAME%'s Documents";Cookies;"Application Data\Sun";temp
Still no luck. Probably the "My Documents" folder needs some tricky naming, but for the sake of me I can't understand why the other one ("Application Data\Sun") doesn't get excluded.
Am I doing something wrong?
Any help is appreciated.
Environment: DC with W2003 R2, TS, File and Print.
The GP Results Wizard run on a few of the users, does not reveal any errors. It says that the winning GPO is the one I intend to apply. Event viewer says GPOs have been applied successfully. Any ideas?
Thanks,
0
Comment
Question by:ricardocoto
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
20 Comments
 
LVL 11

Expert Comment

by:loftyworm
ID: 24809334
Is altering the entriy with surrounding " "  or ' ' change anything?
0
 

Author Comment

by:ricardocoto
ID: 24809571
Hi loftyworm:

When you say the entry, do you refer to the whole string of folder names?

I use " " because an article I read that when using folder names with spaces in between you need to use quotation marks, even if you use a variable such as %APPDATA% because that variable is pointing to a folder names with spaces. I haven't tried single quotation marks yet.

I'll try tonight and let you know, tomorrow.
Thanks,
0
 
LVL 3

Expert Comment

by:jhoncoop
ID: 24810284
The actual issue is that the physical folder is called "My Documents".  Your client interpretes the metadata of the folder and labels it "username's Documents"; however, the actual folder name is still the original "My Documents".  You can actually demonstrate this behavior by browsing the drive via an administrative share over the network.  Often the folders end up with your username's Documents.

I would suggest you just update your GPO to reference "%userprofile%\My Documents" as this is the data you are trying to exclude.

Hopefully this helps!
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 

Author Comment

by:ricardocoto
ID: 24828338
loftyworm: The single quotation didn't work

jhoncoop: I just updated the GPO with your suggestion. Sadly I'll have to wait till Mon to know the results. It is late and everybody has left the office for the weekend.
Have a good weekend and thanks for your help.
Ricardo.
0
 

Author Comment

by:ricardocoto
ID: 24841554
jhoncoop:

I checked today and the "My Documents" folder is still there. BTW your description of what might be happening is exact the opposite. On the client's computer the folder is named "My Documents" but on the server, where the profile is stored, the folder gets the name "USERNAME's Documents". I can't figure it out how to exclude it.
Thanks,
Ricardo
0
 

Author Comment

by:ricardocoto
ID: 24871959
I have more info:
I tried to simplify the list of excluded folders to troubleshoot this issue better, so I left the list as follows:
Cookies;temp;"%APPDATA%"

So far Cookies and temp get excluded, but APPDATA does not. Does the fact that we have users' roaming profiles on a shared folder "E:\Profiles" has anything to do with this issue?

Have any one got any ideas?

I'll try to include another folder that is not set in a variable and see what happens and report it back here.
Thanks,
Ricardo.
0
 
LVL 11

Expert Comment

by:loftyworm
ID: 24872372
Yeah, that is my thought as well, I am wondering if the variable is being passed correctly.  I will look and see how variables are handles in GPO's
0
 

Author Comment

by:ricardocoto
ID: 24872416
loftyworm:
Thanks for your quick response. I did some changes on the profile. I tried to eliminate the variables this time and I'll report back.
Regards,
Ricardo.
0
 
LVL 11

Expert Comment

by:loftyworm
ID: 24872424
This was saying that environment variables may not work;
http://www.eggheadcafe.com/software/aspnet/29542359/environment-variables-in.aspx
0
 

Author Comment

by:ricardocoto
ID: 24926575
More updates:
- The simple "Application Data" as a folder to be excluded in the list didn't work (yes I'm using "" because of the space in the folder name)
- The "%APPDATA%" variable didn't work either (I'm using "" here too because the variable refers to a name that has a space in it)
- The Cookies;temp folders get excluded (There is no need to use "")

Haven't tried any other options for the "My Documents" folder since this one is more complicated because the name changes applied to it by the system (see previous posts). After sorting out why the "Application Data" does not get excluded I'll try with the "My Documents".

Anyone has any ideas?
Thanks,
Ricardo.
0
 
LVL 11

Expert Comment

by:loftyworm
ID: 24927281
Have you tried this
"cookies;temp;%appdata%"
0
 
LVL 11

Expert Comment

by:loftyworm
ID: 24927334
0
 

Author Comment

by:ricardocoto
ID: 24927752
Hi loftyworm:
I haven't tried the suggested list, but I will definitively do it today and see what happens. Regarding the post on the link, the issue this particular user was having was with redirection. I'm just trying to exclude from the roaming profile which should be more simple.
Anyways I appreciate your time and effort and will let you know the outcomes of the proposed form.
I'm sorry if this is going slow but I'm a one man IT shop, and as you might guess they keep me really busy.
Thanks,
Ricardo.
0
 

Author Comment

by:ricardocoto
ID: 25015453
loftyworm:
Tried the last suggestion, no joy. I don't know whether to close this question or not given there aren't any other suggestions. At this point I feel really frustrated. I'm going to make a last attempt to contact MS support to see if they can offer a solution.
Thanks for all your help.
Ricardo.
0
 

Author Comment

by:ricardocoto
ID: 25036722
For the admin or moderator:
I don't know what to do with this question since there are no responses. Please advice.
Thanks,
0
 
LVL 11

Expert Comment

by:loftyworm
ID: 25071132
Ricardo,
Sorry, I was out of town for a while.
I am out of ideas.  You may contact a moderator by selecting the "Request attention" at the top of the article, at the end of your post.  They can close or may be able to notify other experts to take a second look at this.
0
 
LVL 6

Accepted Solution

by:
pilozite earned 2000 total points
ID: 25078184
Hello,

try with this syntax as explained here : http://www.gpanswers.com/fireboard?func=view&catid=2&id=4551

Avoid using double quote for each value, simple something like :

My Documents;Recent;Application Data\Sun

this should works.
0
 

Author Closing Comment

by:ricardocoto
ID: 31601358
THANK YOU!!!! pilozite:
I can not express my gratitude enough! That made the trick.
I will give you all the points, I think you deserve it. By following the comments in the linked post I could resolve it in minutes.
One more time thank you and have a good day!
Ricardo,
0

Featured Post

Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
Suggested Courses
Course of the Month10 days, 19 hours left to enroll

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question