[gptalk] Re: Access Denied on Roaming Profile Folder(s)

  • From: hboogz <hboogz@xxxxxxxxx>
  • To: gptalk@xxxxxxxxxxxxx
  • Date: Tue, 28 Nov 2006 13:58:28 -0500

I am trying to access the folder and its subfolders directly from the
server. Sometimes i need to copy profiles for backup purposes or throw
application specific .ini files.

In this instance i backedup a .pst file previously and need to place it in
the users my doucments profile folder, but can't.

any ideas ?

On 11/28/06, hans straat <hstraat@xxxxxxx> wrote:

The policy "add administrators group to roaming profiles" only applies to
newly created roaming profiles. Otherwords to new users.
If you applied the GPO and profiles were already created you have to use
xcacls or cacls to modify the permissions to the excisting profiles.
But be carefull with the xcacls or cacls command you can also ruin it in a
few commands from the command prompt! TEST before implement it on all

Hans Straat

From: darren@xxxxxxxxxx
To: gptalk@xxxxxxxxxxxxx
Subject: [gptalk] Re: Access Denied on Roaming Profile Folder(s)
Date: Tue, 28 Nov 2006 10 <javascript:void(0)>:15:56 -0800

 How are you trying to access the profile exactly? Is this for a user who
is logged on as themselves and they get access denied on their own folders
or are you trying to access a roaming profile on the server as an
administrator? Because, by default, Administrators are not granted access to
profiles.  And, I'm not sure but I believe that policy you set below only
helps at profile creation time.

*From:* gptalk-bounce@xxxxxxxxxxxxx [mailto:gptalk-bounce@xxxxxxxxxxxxx] *On
Behalf Of *hboogz
*Sent:* Tuesday, November 28, 2006 10 <javascript:void(0)>:03 AM
*To:* gptalk@xxxxxxxxxxxxx
*Subject:* [gptalk] Access Denied on Roaming Profile Folder(s)

Hey Everyone,

I have a problem with roaming Profiles/Folders.

Every time i want to access the folders of each respective roaming profile
but i keep getting an access denied.

The share permission is set to full control for everyone

The NTFS permission of the folder is set to Read+Write for ALL users.

The NTFS permissions of the drive has everyone set to Read+Write .

Even when i've changed all permissions set to Full Control for Everyone, i
still get this message.

In the GPO where folder redirection is enabled and Roaming Profiles is
i've enabled "Add Administrators Group to Romain Profiles"

i understand there is the dsacls command, but would know whether it would
be pertinent to this issue and if so, what would the syntax be ?




Other related posts: