Solved

Help with event id 1526 "Windows did not load your roaming profile

Posted on 2009-07-09
7
2,394 Views
Last Modified: 2012-05-07

We are running Presentation Server 4.5 with now almost 50 machines in our farm.

We get this in the event log (randomly) and sometimes 20 users in a day and sometimes just 5. Event ID: 1526

Windows did not load your roaming profile and is attempting to log you on with your local profile. Changes to the profile will not be copied to the server when you logoff. Windows did not load your profile because a server copy of the profile folder already exists that does not have the correct security. Either the current user or the Administrator's group must be the owner of the folder. Contact your network administrator.

 

We have tried using the xcacls from http://www.brianmadden.com/forums/t/26502.aspx for all users on the tsprofiles server and then deleting their profile on all 50 servers in \documents adn settings\%username% and that works for that user for a day, or even a week and then it starts over again.  Any ideas as to how to finally make this go away for good.  This is really getting annoying in farm of almost 50 servers and 2500 users.  

We do have a GPO that is setup as

 Administrative Templateshide
Policy definitions (ADMX files) retrieved from the local machine.System/Group Policyhide
Policy Setting Comment
User Group Policy loopback processing mode Disabled  

System/User Profileshide
Policy Setting Comment
Delete cached copies of roaming profiles Enabled  

Windows Components/Terminal Services/Terminal Server/Connectionshide
Policy Setting Comment
Set rules for remote control of Terminal Services user sessions Enabled

and also a redirect policy for the users with:

Windows Settingshide
Folder Redirectionhide
Documentshide
Setting: Basic (Redirect everyone's folder to the same location)hide
Path: \\meanserver\Private$\%USERNAME%\MyDocs
Optionshide
Grant user exclusive rights to Documents Disabled
Move the contents of Documents to the new location Disabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems Enabled
Policy Removal Behavior Restore contents

Musichide
Setting: Follow the Documents folder
Pictureshide
Setting: Follow the Documents folder
Videoshide
Setting: Follow the Documents folder

if that helps.  Please help! thanks!

0
Comment
Question by:The_Spaz
  • 3
  • 3
7 Comments
 
LVL 14

Expert Comment

by:amichaell
ID: 24818363
Are you running UPHClean on your servers?  If not, give that a shot.  Sometimes a profile will not delete itself as it may have a handle open.  UPHClean closes those handles allowing the profile to delete itself upon user logoff.  
0
 
LVL 14

Expert Comment

by:robincm
ID: 24822439
Yes use UPHClean always (even if you're not getting this problem).
http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=1b286e6d-8912-4e18-b570-42470e2f3582

How are you setting the location to store the roaming profiles?
Group policy or via the user account configuration in active directory?
Check permissions on that folder/share.
Are any profiles being saved back?
Could be AV scanning on the file server used to hold the roaming profiles locking one of the files and preventing the terminal server copying it at user logon. Try temporarily excluding the profiles folder. Check for locked files on the file server and see what has them locked (probably use process explorer).
0
 
LVL 1

Author Comment

by:The_Spaz
ID: 24824860
Sorry forgot to mention that
yes. We are already running UPHClean on all machines and the setting for roaming profiles is in Active Directory.  Also, incase you are going to ask if the place for the profile and the tsprofile are in different places that answer is also yes (as recommended by Citrix).

0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 14

Expert Comment

by:robincm
ID: 24839947
ok:
Are any profiles being saved back?

Could be AV scanning on the file server used to hold the roaming profiles locking one of the files and preventing the terminal server copying it at user logon. Try temporarily excluding the profiles folder. Check for locked files on the file server and see what has them locked (probably use process explorer from sysinternals (free)).
Is it a Windows server holding the romaing profiles?
0
 
LVL 1

Author Comment

by:The_Spaz
ID: 24840429
We have verified the AV server is not Holding the profile(s) and yes all 50 (almost) are running Windows Server 2003 with the latest patches with Presentation Server 4.5.

Keep bringing the suggestions this way, please...
0
 
LVL 1

Accepted Solution

by:
The_Spaz earned 0 total points
ID: 24843521
Here is what I have done which we will find out in a few days if it has resolved the issue. I deleted all the users profiles from each server in c:\documents and settings\%username% and then created a script that goes thru on the tsprofile server and runs the following for each user.
subinacl.exe /file e:\data\tsprofiles\%1 /setowner=Administrators
subinacl.exe /subdirectories e:\data\tsprofiles\%1\*.* /setowner=Administrators
XCACLS e:\data\tsprofiles\%1 /C /G BCH\%1:F system:F %COMPUTERNAME%\Administrators:F "CORP\domain admins":F /T /y
This is essentialy based of the Knowledge base article
http://support.microsoft.com/default.aspx?scid=kb;en-us;327462
but it then also gives the Domain Admins rights to their TSProfiles incase we need to fix down the road.   Since we have over 400 users and soon to be 2500 I created a users.txt file that had all the users in it that called the above.  Here is that script:
@echo off
for /f %%i in (users.txt) do call fixservers.cmd %%i
and the permission part above is called fixservers.cmd.   Again, I will look again at this in a few days and repost if it has fixed the problem for all or not.
0
 
LVL 14

Expert Comment

by:robincm
ID: 24847555
Check the permissions on the folder that is shared out for the roaming profiles (i.e. e:\data\tsprofiles).
Should be:
Administrators: full control
Creator Owner: full control
Users: Special (list and create folders only)
This assumes your users are a member of domain users, and domain users is a member of the local users group no the server hosting e:\
There is a policy setting you should apply to your terminal servers to give admins access to profiles:
Computer configuration, administrative templates, system, user profiles:
Add the Administrators security group to roaming user profiles
You might also like to use the Delete cached copies of roaming profiles policy, and if you get it all working also turn on the Do not log users on with temporary profiles policy. I have all three on and have no problems. The latter is handy as it doesn't confuse your users with wierd looking desktops - though it assumes that your profiles share is pretty highly available.
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Citrix XenDesktop, Citrix Studio, Citrix Policies, Citrix XenApp
#Citrix #XenApp #Citrix Scout #Citrix Insight Services #Microsoft VMMAP #Microsoft ADEXPLORE #Microsoft RAMMAP #Microsoft TCPVIEW #Microsoft AUTORUNS #Microsoft PROCESS EXPLORER #Microsoft PROCESS MONITOR
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now