文件夹重定向仅在我运行 gpupdate /force 时才适用 - 文件服务器迁移

文件夹重定向仅在我运行 gpupdate /force 时才适用 - 文件服务器迁移

我们刚刚将大约 2300 名用户的主共享迁移到新的文件服务器。出于某种原因,文件夹重定向不会更新任何现有用户配置文件的路径(我们不使用漫游配置文件)。但是,如果我在gpupdate /force该个人用户登录到他们已有配置文件的 PC 时运行,文件夹重定向将正确应用。由于我们的用户经常四处移动,这正在成为一个大问题。

在每个用户的“配置文件”选项卡下的活动目录中,我们已经设置: Connect: Z: To: \\FileServer\Share\Username 这很好用。

尽管很久以前删除了 XP,但我们尚未从 XP 布局更改文件夹结构(即图片、音乐等仍然在文档内),因此我们的重定向策略如下:

链接到包含我们用户帐户的 OU 的用户配置

文件

  • 基本 - 将每个人的文件夹重定向到同一位置
  • 重定向到用户的主目录
  • 授予用户对文档的专有权利
  • 删除策略后将文件夹保留在新位置

图片关注 Documents 文件夹

音乐关注 Documents 文件夹

视频关注 Documents 文件夹

桌面

  • 基本 - 将每个人的文件夹重定向到同一位置
  • 重定向到以下位置:%HOMESHARE%\Desktop
  • 删除策略后将文件夹保留在新位置

收藏夹

  • 基本 - 将每个人的文件夹重定向到同一位置
  • 重定向到以下位置:%HOMESHARE%\Favorites
  • 删除策略后将文件夹保留在新位置

计算机配置链接到包含我们计算机的 OU

策略\管理模板\系统\组策略:

  • 配置文件夹重定向策略处理
    Process even if the Group Policy objects have not changed: Enabled

共享权限:

  • 员工:完全控制
  • 域管理员:完全控制

共享文件夹的 NTFS 权限:

遗传:残疾

  • 创建者所有者:完全控制(仅限子文件夹和文件)
  • 系统:完全控制(此文件夹、子文件夹和文件)
  • 管理员:完全控制(此文件夹、子文件夹和文件)
  • 域用户:遍历文件夹/执行文件、列出文件夹/读取数据、读取属性、创建文件夹/附加数据(仅限此文件夹)

这是 的结果gpresult /user username /v。我删除了所有多余的策略以使其更短。我添加它的原因是为了显示文件夹重定向策略未被过滤掉等,并且报告的文件夹重定向部分显示N/A。如果您需要了解我启用的任何其他策略,请询问。

RSOP data for DomainRemoved\UserRemoved on F701 : Logging Mode
-------------------------------------------------------------

OS Configuration:            Member Workstation
OS Version:                  10.0.14393
Site Name:                   Removed
Roaming Profile:             N/A
Local Profile:               C:\Users\UserRemoved
Connected over a slow link?: No


COMPUTER SETTINGS
------------------
    CN=F701,OU=F7,OU=IT Computers,OU=First Floor,OU=Main Block,OU=Computers,OU=Company,DC=domain,DC=removed
    Last time Group Policy was applied: 08/07/2017 at 13:11:32
    Group Policy was applied from:      DCName.domain.removed
    Group Policy slow link threshold:   500 kbps
    Domain Name:                        DomainRemoved
    Domain Type:                        Windows 2008 or later

    Applied Group Policy Objects
    -----------------------------
        Internet Connection & Firewall Policy
        BootCamp Fixes
        Interactive Logon Policy
        Fix Daylight Savings
        Win10 Computer Policy
        Computer Software Restrictions (AppLocker)
        Apogee Printers
        Temp Fix for Folder Redirection
        Default Domain Policy

    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
        Whole School Software Win7
            Filtering:  Denied (WMI Filter)
            WMI Filter: Apply to Windows 7 Only

        Win 7 Computer Policy Extension
            Filtering:  Denied (WMI Filter)
            WMI Filter: Apply to Windows 7 Only

        Local Group Policy
            Filtering:  Not Applied (Empty)

        Computer Policy
            Filtering:  Denied (WMI Filter)
            WMI Filter: Apply to Windows 7 Only

    The computer is a part of the following security groups
    -------------------------------------------------------
        BUILTIN\Administrators
        Everyone
        BUILTIN\Users
        NT AUTHORITY\NETWORK
        NT AUTHORITY\Authenticated Users
        This Organization
        F701$
        Domain Computers
        Authentication authority asserted identity
        CERTSVC_DCOM_ACCESS
        System Mandatory Level

    Resultant Set Of Policies for Computer
    ---------------------------------------

         Administrative Templates
        ------------------------

    REMOVED EXCESS POLICIES TO SHORTEN

            GPO: Win10 Computer Policy
                Folder Id: Software\Policies\Microsoft\Windows\NetCache\NoMakeAvailableOffline
                Value:       1, 0, 0, 0
                State:       Enabled

            GPO: Temp Fix for Folder Redirection
                Folder Id: Software\Policies\Microsoft\Windows\Group Policy\{25537BA6-77A8-11D2-9B6C-0000F8080861}\NoSlowLink
                Value:       1, 0, 0, 0
                State:       Enabled

            GPO: Default Domain Policy
                Folder Id: Software\Policies\Microsoft\Windows NT\CurrentVersion\Winlogon\SyncForegroundPolicy
                Value:       1, 0, 0, 0
                State:       Enabled

            GPO: Temp Fix for Folder Redirection
                Folder Id: Software\Policies\Microsoft\Windows\Group Policy\{25537BA6-77A8-11D2-9B6C-0000F8080861}\NoGPOListChanges
                Value:       0, 0, 0, 0
                State:       Enabled

USER SETTINGS
--------------
    CN=Users Name,OU=Teaching Staff,OU=Staff,OU=Company,DC=domain,DC=removed
    Last time Group Policy was applied: 08/07/2017 at 12:22:59
    Group Policy was applied from:      N/A
    Group Policy slow link threshold:   500 kbps
    Domain Name:                        DomainRemoved
    Domain Type:                        Windows 2008 or later

    Applied Group Policy Objects
    -----------------------------
        Internet Connection & Firewall Policy
        Folder Redirection Policy
        Smoothwall Staff Proxy Settings
        Screensaver
        Win10 Base User Policy
        Win10 Staff Policy
        Apogee Printers
        Default Domain Policy

    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
        Staff
            Filtering:  Denied (WMI Filter)
            WMI Filter: Apply to Windows 7 Only

        Win 7 Staff Policy
            Filtering:  Denied (WMI Filter)
            WMI Filter: Apply to Windows 7 Only

        Local Group Policy
            Filtering:  Not Applied (Empty)

    The user is a part of the following security groups
    ---------------------------------------------------
        Domain Users
        Everyone
        BUILTIN\Users
        NT AUTHORITY\INTERACTIVE
        CONSOLE LOGON
        NT AUTHORITY\Authenticated Users
        This Organization
        LOCAL
        WiFi Access
        PaperCut Welsh Bacc
        PaperCut Welsh Bacc Adv
        Staff
        Smoothwall Staff
        Admin Network Users
        PaperCut Computing
        HoD
        CERTSVC_DCOM_ACCESS
        Medium Mandatory Level

    The user has the following security privileges
    ----------------------------------------------

        Bypass traverse checking
        Increase a process working set
        Shut down the system
        Remove computer from docking station

    Resultant Set Of Policies for User
    -----------------------------------

        Administrative Templates
        ------------------------

    REMOVED EXCESS POLICIES TO SHORTEN

        Folder Redirection
        ------------------
            N/A

我们正在迁移到虚拟服务器,但尚未移除旧 DC。因此,我们目前有 5 个混合操作系统的 DC:

2 个服务器 2016
1 个服务器 2012
2 个服务器 2008 R2

我们的森林和域功能级别目前都是 2008 R2。

我们的客户端电脑是 Windows 10 1607 64 位。

我已尝试提供尽可能多的信息,但如果您需要其他信息,请询问。

编辑:

未启用环回处理。RSoP.msc
未显示任何错误。gpresult
HTML 输出显示:文件夹重定向成功 703 毫秒

相关内容