Senior admins cannot create a roaming profile that a user can access. Error states folder doesn't have correct security
Posted on 2014-10-03
The process to create a new account involves manually creating the profile folder and assigning modify rights (ntfs) for the end user. I know this isn't the best way but I don't have the ability to change that just yet. There are only three accounts that get inherited rights on the profile folder. One is a technician(modify), the other is senior admin (Full) and then the system account (full). I'm thinking that the administrators of the server that the fileshare resides on needs to have full permissions also. Nevertheless, when a senior admin creates the folder, the end user's profile doesn't copy. The error states the folder already exists and has the incorrect security. If the domain admin creates the folder, there is no issue. Looking at ownership of the folder in both situations indicates the senior admin created folder shows ownership for that senior admin's name. If the doamin admin creates it, the ownership shows the administrators of the file share server is the owner. What's the best way to fix this understanding that a senior won't have domain admin permissions?