Solved

local & domain path query

Posted on 2013-12-31
7
450 Views
Last Modified: 2014-01-01
hi I am running a win 2003 domain and getting ready to migrate across to win 2008.

I have noticed something unusual and wanted to know if anyone can provide any advice.

step 1

usually I install win 2003 on the physical server and join as a member server to the domain.  when I then open up the cmd prompt it shows the following path:

c:\documents and settings\administrator.domainname>

if I logon to this same member server (locally) and open the cmd prompt it shows the following as expected:

c:\documents and settings\administrator>

step 2

I have installed from a win 2003 cd the image onto my ris member server.

I then logged onto my (aduc) and pre-staged my isa 2006 firewall by adding the name: isa-20061a & the mac address successfully.

I then rebooted my other server and selected (f12) and installed win 2003 image successfully.

on completion of install I logged on as the domain administrator as it does not currently have a (local account) like (step 1) above as expected.  I then opened up the cmd prompt:

c:\documents and settings\administrator>

I then created a new (local account) and opened up the command prompt and saw:

c:\documents and settings\administrator.isa-20061a>

question 1.  why is (step 1 different from step 2)  ?
0
Comment
Question by:mikey250
  • 4
  • 3
7 Comments
 
LVL 56

Accepted Solution

by:
Cliff Galiher earned 500 total points
Comment Utility
That is completely normal and expected. Windows will always attempt to use just the account name when creating a profile directory. If it detects that the directory name already exists, then it appends the domain name for domain accounts or the machine name for local accounts to avoid the conflict. And if THAT already exists, it will start appending numbers counting upwards.

So which appended name you see will depend on which account got just the "administrator" directory first... domain or local.... and then the conflict resolution above kicks in.
0
 

Author Comment

by:mikey250
Comment Utility
hi cgaliher,

important note:

what I forgot to mention before you read the below issue, originally I installed upto 99% of the updates sent from my wsus and did not have this issue below, but since completing a 2nd clean ris image install, I have not installed updates upto 99%.  I just assumed because sp2 was installed I would not have this problem below now, but I do as below now shows.

the reason for installing all updates upto 99% locally was because the wsus server detects my member server but as soon as I install isa 2006 it no longer detects this isa server via my wsus server, even though updates are passed across, but I only realise this when I physically logon to my isa server and see that some updates are ready to install, except for those that install automatically that do not require a 'restart' due to my 'gpo settings'.

my isa has however detected via logging on locally '8 updates' so I am installing them now as my wsus has not pushed any updates down yet via the domain logon as clearly there has not been enough time for everything to sync up.

------------------------------------------------------

thanks for those comments.  I have always installed 'win 2003' directly on the pc and not via a 'ris flat image'.

I have attached some screenshots of the messages I get.

step 1.

I logged onto the domain and attempted to install 'sp2' but I received a message about not having the rights.

resolution - I logged on locally and installed sp2 successfully

step 2.

I attempted to install 'isa 2006' but it stated:  'the system administrator has set policies to prevent this installation.

question 1.

resolution fail -  I logged back onto my master dc selected: ou - for isa 2006 & right clicked 'properties' & selected 'members of' tab and added: domain admin & the delegation tab & selected: 'trust this computer for delegation to any service (Kerberos only) - but I still receive the same error - why ?

question 2.  what I do not understand is if I copied the win 2003 image onto my 'ris domain member serverr' successfully and rebooted the other server which allowed me to select the 'win 2003 image' and logon with 'domain admin' account, then why do I now not have permission as an administrator  ?

note: when I check the 'eventviewer' it states:

security - unable to complete the operation on 'security'.  access denied
sp2---isa-2006-dont-have-permiss.docx
0
 
LVL 56

Expert Comment

by:Cliff Galiher
Comment Utility
To effectively use RIS, you need to generalize the image. When you don't do that, security permissions get smashed during the deployment. This restriction is true for WDS and MDT as well.
0
Complete Microsoft Windows PC® & Mac Backup

Backup and recovery solutions to protect all your PCs & Mac– on-premises or in remote locations. Acronis backs up entire PC or Mac with patented reliable disk imaging technology and you will be able to restore workstations to a new, dissimilar hardware in minutes.

 

Author Comment

by:mikey250
Comment Utility
hi, I have never had this problem before as I normally install win 2003 os, on the physical machine.

yes if I was to use 'sysprep' then I remember seeing 'generalize', but I did not use that as it was not need hence only been using: riprep.exe as my machines are all identical.

im assuming 'delegation' enabling 'batch job or service or add machines to network' are not the answers then.
0
 
LVL 56

Expert Comment

by:Cliff Galiher
Comment Utility
Generalizing isnt just about hardware. It also properly scrubs SIDs, otherwise you get conflicts in the domain which absolutely breaks delegation.

we seem to be gong farther and farther from your originally posted question though. You asked why the two scenarios creates two different folder structures. that has been addressed and would NOT create permissions issues like you describe. So what you are describing now is unrelated to your initial question. Even at that, I have tried to assist you with information on the "right" way to fix your issue. The workarounds you suggest would not work. But I don't want to play whack-a-mole and get new twists with every update. So, with that, I will simply wish you luck.
0
 

Author Comment

by:mikey250
Comment Utility
hi, my original question yes you did answer my question, but due to installing 'isa firewall' and receiving the following message:

"the system administrator has set policies to prevent this installation"

I just assumed it was something to do with my main thread hence asking that last secondary question.

yes i have read about 'sysprep' which is for 3rd party software which i am not currently using.

ok i will close thread and appreciated for the main thread advice.
0
 

Author Closing Comment

by:mikey250
Comment Utility
sound advice!  much appreciated.
0

Featured Post

Want to promote your upcoming event?

Is your company attending an event or exhibiting at a trade show soon? Are you speaking at a conference? Spread the word by using a promotional banner in your email signature. This will ensure your organization’s most important contacts are in the know.

Join & Write a Comment

To effectively work with Diskpart on a Server Core, it is necessary to write some small batch script's, because you can't execute diskpart in a remote powershell session. To get startet, place the Diskpart batch script's into a share on your loca…
Learn about cloud computing and its benefits for small business owners.
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now