Solved

Using variables in Home drive path in AD   -  group policy

Posted on 2015-02-06
10
685 Views
Last Modified: 2015-02-07
Hi there,
Running server 2008 R2 domain.  Need to do:
1) Hide the home drive paths from the user sessions.  Example At the moment all users get the   H:\\server\AllStudents\grade1\Jmisha   mapped.  How/where I can make changes in GPO to have users only see 'H:' instead of the full server path.

2) In the Ad user properties, profile tab, home folder  I simply put \\server\AllStudents\grade1\%username% and the home folder with appropriate permissions is made under 'Each Grade'.  Keeping in mind that the number after the 'grade' changes for each user in different grades what variable path I can put in so that the user home folders are successfully created for each grade.  Example:
\\server\AllStudents  = is a permanent path
grade(number)\%username% = is a variable path.  What can I use for grade(number)?

Need help
0
Comment
Question by:amanzoor
  • 4
  • 3
  • 3
10 Comments
 
LVL 32

Expert Comment

by:it_saige
ID: 40593931
The variables in question are set on the client.  Potentially you could create a new environment variable that is retrieved via a script mechanism for the Grade Number (I'm just not certain in the scheme of things if scripts are ran before the home folder is set or after, you may have to do some testing, otherwise, you may have to use a login script to map the drive for you).

As for setting an environment variable.  What operating system is on your client computers?  If they are all Vista and above you can use SETX to set an environment variable; i.e. -
SETX GRADENUMBER "grade1" /M

Open in new window

Then you could reference it in your Home Directory setting as -
\\server\AllStudents\%gradenumber%\%username%

Open in new window


-saige-
0
 
LVL 35

Accepted Solution

by:
Mahesh earned 250 total points
ID: 40594468
By default windows sets the mapped drive label with the associated path. Through GPO, you can set a label to the mapped drive under "Label as" option.
Create new GPO, in GPO under user configuration\preferences use drive map GP Preferences and create new home drive as drive map, do not forget to select "Run in logged user security context, otherwise GPO preference will not apply
Apply this GPO to OU containing users
If you have XP machines, download CSE for XP and install it on XP  to apply GP preferences item

Attached here settings
Drive MapCommon tab setting
Either you have to use the GPO or use logon script to map drive and rename it.
http://gallery.technet.microsoft.com/scriptcenter/​7dd02dca-d177-478b-9a20-d0210413ab2d
0
 
LVL 4

Author Comment

by:amanzoor
ID: 40594492
Mahesh and Saige;
Saige is suggesting to create the environment variable first.  Please look under preferences, drive maps, Environment.  I need help making this for my 'grade1' 'grade2'............................so on
Then I can put this path in the drive maps like:
\\server\allstudents\%grade(1)(2)(3)......%\%username%.  Please help me how to make the environment variable for:
grade(number) where number is the variable.
Thanks
0
 
LVL 32

Expert Comment

by:it_saige
ID: 40594501
The first question, then, is where is the grade number stored? If it is stored in Active Directory, which property are you assigning it to?

-saige-
0
 
LVL 4

Author Comment

by:amanzoor
ID: 40594560
Saige,
It saves the folders on '\\server' If I want to make a home drive for a group of users in the same OU, I simply highlight them, go to profile tab, in the home drive select H: and put the path like \\server\Allstudents\grade2\%username%.  So under this server, AllStudents I can see folders of all grades(grade1, grade2.....................)  I am trying to play around with Environment in preferences (not productive as yet).  Need help
0
Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

 
LVL 35

Expert Comment

by:Mahesh
ID: 40594640
Anyways you have to enter grade in form of environmental form in home directory path, what I mean you cannot keep it common for all users just like %username%, it will apply to all users
According to my understanding, you can't achieve what you want by deploying environmental variables because you have multiple grades and for that you do require multiple variables defined
Further more it will not hide grade folder

Better you could deploy GP Preferences with "Label As" it will hide home drive path

If you wanted that user would not be able to locate path on server directly, you could enable access based enumeration on server share
Also you need to replace authenticated users with specific students group having same grade on each grade folder
0
 
LVL 32

Assisted Solution

by:it_saige
it_saige earned 250 total points
ID: 40594868
I understand that you save the folders as grade1, grade2, etc.  But how do you determine the students grade level?  Normally, you would create an (or use an existing) attribute in order to identify the students grade level.

To create a custom attribute you could do the following:

1. Register schmmgmt.dll

Open an administrative command prompt.Type in 'regsvr32 schmmgmt.dll' and press enter.You should receive a message that schmmgmt.dll registration succeeded.  Press OK to acknowledge the message box.

2. Open the Active Directory Schema mmc snap-in

Open the Microsoft Management Console (mmc.exe).With the Microsoft Management Console open, select File --> Add/Remove Snap-in...In the Add or Remove Snap-ins Dialog, choose 'Active Directory Schema' and click 'Add'.Once added in the Selected snap-ins tree, click OK.

3. Add a new attribute for gradeLevel (or any other name that will assist you with identifying the attribute). Note: In order to add an attribute, you must be a member of the Schema Admins administrative group.

Expand the Active Directory Schema tree.Right-click on 'Attributes' and select 'Create Attribute...'.Click 'Continue' to acknowledge the warning.Since we are dealing with Grade Levels, I chose a syntax of Enumeration with a Minimum value of 0 (Kindergartener) and 12 (High School Senior).Note: You must enter a valid Unique X500 Object ID.  You can generate a valid object id by using the script presented here: https://gallery.technet.microsoft.com/scriptcenter/56b78004-40d0-41cf-b95e-6e795b2e8a06After refreshing the Attributes, you can see your new attribute defined.

4. Assign the attribute to the user class.

Select the Classes tree.Right-click on the user class object and choose 'Properties'.Select the 'Attributes' tab, and press 'Add'.Locate and select the attribute you just added.  Press OK to add the attribute.After adding the attribute.  Press OK.You can then use a script, powershell or ADSI Edit to modify the custom attributes for your users.  Conversely, you can then use a script to get the custom attribute for the user in order to assign it to an environment variable.

Edit:  Another idea (using the custom attribute) is to use the powershell presented here, in order to not only create but set the user's home directory.

-saige-
0
 
LVL 4

Author Closing Comment

by:amanzoor
ID: 40595706
Thanks guys,
Really appreciate your time.
I was able to achieve what I needed in a very simple way as Mahesh guided,
-Simple connected the Mapped drive in General tab under preferences 'REPLACE' H: to the \\server\Allstudent\grade1\%logonuser%, labeled it 'HOMEDRIVE'  In the common tab, simple pull up the OU in which the users for grade1 reside.
-Do all Maps for H drive for each grade level, and in Common tab keep on pulling down the corresponding OU.
-In the properties of the user in AD, does not matter even if the user already has the H drive mapped to  \\server\Allstudent\grade1\%logonuser% the REPLACE map drive takes care of this.
-End result, I tried with each user in each OU and wallah, I simply got 'HOME DRIVE H:, nicely  mapped to users homedrives.
-no need to tweak down to variable level.
0
 
LVL 35

Expert Comment

by:Mahesh
ID: 40595773
Instead of "Replace" select "Update"

What it will do, it will create map drive 1st time, next time it will look for map drive with appropriate path and if found wrong path, it will just update it to correct one,
if correct path found just skip it

@It_Saige:
Thanks for excellent walk through wrt new attribute creation.
Thank You.
0
 
LVL 32

Expert Comment

by:it_saige
ID: 40595795
@Mahesh - Thanks for the compliment.

@amonzoor - Glad you got it sorted out.

-saige-
0

Featured Post

Free camera licenses with purchase of My Cloud NAS

Milestone Arcus software is compatible with thousands of industry-leading cameras for added flexibility. Upon installation on your My Cloud NAS, you will receive two (2) camera licenses already enabled in the software. And for a limited time, get additional camera licenses FREE.

Join & Write a Comment

Some time ago I was asked to set up a web portal PC to put at our entrance. When customers arrive, they could see a webpage 'promoting' our company. So I tried to set up a windows 7 PC as a kiosk PC.......... I will spare you all the annoyances I…
Let’s list some of the technologies that enable smooth teleworking. 
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now