Solved

Administrator account and a roaming profile

Posted on 2010-09-11
2
830 Views
Last Modified: 2012-06-21
We have added a certificate root server to our network to implement NAP. We use automatic certificate enrollment. The automatic enrollment GPO isn’t scoped to the administrator. The administrator account doesn’t have a roaming profile. Now that 802.1x is activated, when I login to a computer with 802.1x enabled, using the administrator account, the network connection gets blocked after the reauthentication, because the administrator doesn’t have a user certificate. I can’t link a GPO to the Build In User OU, in which the administrator account is located. Now I can add the administrator to the scope of the automatic enrollment GPO. But then the administrator gets a new certificate during every login to a computer, on which there wasn’t a user certificate enrolled yet to the local profile. Then I have to change the profile of the administrator to a roaming profile. Also I have to create and link a GPO to the administrator to prevent the Desktop and Startmenu and Documents to roam. To make this work I have to create a GPO with loopback processing, scoped to the administrator. But because the loopback policy is a Computer policy, I also have to add all the computers to the scope of this loopback GPO.  Or I can also move the administrator account to an OU to which a GPO can be linked.

Or also I can stop using THE administrator account, disable the account as usually advised by Microsoft,  and create a new user account with the same rights and privileges and add it to the User OU to get the certificate with auto enrollment and prevent the Desktop and Startmenu and Documents to roam.

I’m looking for advise and tips how you are solving this in your domain?
0
Comment
Question by:NicoNL
2 Comments
 
LVL 4

Accepted Solution

by:
Sean_D76 earned 500 total points
ID: 33655114
No experience with NAP but from reading this two things crossed my mind:
1.) You can't link a GPO to the Users folder where Administrator resides, BUT you can link the GPO at the top (domain level) and set the "Applies to" security option to be "Administrator" only.

2.) You don't have to auto-enroll just to get a cert. There is a manual way... check the IIS on your cert server but there is probably a new site there like /certserv or something.  Go to that page while logged in as administrator and I believe there is an option for enrolling yourself.

Furthermore, I'm a bit confused on why you think a new cert will be issued every time you login as admin unless you use roaming profiles.  The cert gets stored in AD with the user object and should not change on a per PC basis.  If it did you'd have serious problems with EFS files and such.   So really I think there would be no downside to letting the auto-enroll GPO affect the Administrator account as well.  Admittedly this is not one of my stronger areas though so maybe I'm missing something here?
0
 

Author Comment

by:NicoNL
ID: 33656113
Link the GPO at the top scoped only to the Administrator, yes that's indeed the way to push the auto enrollment to the administrator. Then I don't have to change the administrator's profile to roaming.

You made my day :-)
I just tested it and it works. Now I won't be having network verification errors on computers with 802.1x enabled, logged in as the administrator, great!

0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you migrate a Terminal Server licenses server inside the 2008 server family, you can takte advantage of the build-in migration tool. If you like to migrate an older 2003 Server (and the installed client CALs) to a 2008 R2 server for example, you …
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

29 Experts available now in Live!

Get 1:1 Help Now