我们刚刚将大约 2300 名用户的主共享迁移到新的文件服务器。出于某种原因,文件夹重定向不会更新任何现有用户配置文件的路径(我们不使用漫游配置文件)。但是,如果我在gpupdate /force
该个人用户登录到他们已有配置文件的 PC 时运行,文件夹重定向将正确应用。由于我们的用户经常四处移动,这正在成为一个大问题。
在每个用户的“配置文件”选项卡下的活动目录中,我们已经设置:
Connect: Z: To: \\FileServer\Share\Username
这很好用。
尽管很久以前删除了 XP,但我们尚未从 XP 布局更改文件夹结构(即图片、音乐等仍然在文档内),因此我们的重定向策略如下:
链接到包含我们用户帐户的 OU 的用户配置
文件
- 基本 - 将每个人的文件夹重定向到同一位置
- 重定向到用户的主目录
- 授予用户对文档的专有权利
- 删除策略后将文件夹保留在新位置
图片关注 Documents 文件夹
音乐关注 Documents 文件夹
视频关注 Documents 文件夹
桌面
- 基本 - 将每个人的文件夹重定向到同一位置
- 重定向到以下位置:
%HOMESHARE%\Desktop
- 删除策略后将文件夹保留在新位置
收藏夹
- 基本 - 将每个人的文件夹重定向到同一位置
- 重定向到以下位置:
%HOMESHARE%\Favorites
- 删除策略后将文件夹保留在新位置
计算机配置链接到包含我们计算机的 OU
策略\管理模板\系统\组策略:
- 配置文件夹重定向策略处理
Process even if the Group Policy objects have not changed: Enabled
共享权限:
- 员工:完全控制
- 域管理员:完全控制
共享文件夹的 NTFS 权限:
遗传:残疾
- 创建者所有者:完全控制(仅限子文件夹和文件)
- 系统:完全控制(此文件夹、子文件夹和文件)
- 管理员:完全控制(此文件夹、子文件夹和文件)
- 域用户:遍历文件夹/执行文件、列出文件夹/读取数据、读取属性、创建文件夹/附加数据(仅限此文件夹)
这是 的结果gpresult /user username /v
。我删除了所有多余的策略以使其更短。我添加它的原因是为了显示文件夹重定向策略未被过滤掉等,并且报告的文件夹重定向部分显示N/A
。如果您需要了解我启用的任何其他策略,请询问。
RSOP data for DomainRemoved\UserRemoved on F701 : Logging Mode
-------------------------------------------------------------
OS Configuration: Member Workstation
OS Version: 10.0.14393
Site Name: Removed
Roaming Profile: N/A
Local Profile: C:\Users\UserRemoved
Connected over a slow link?: No
COMPUTER SETTINGS
------------------
CN=F701,OU=F7,OU=IT Computers,OU=First Floor,OU=Main Block,OU=Computers,OU=Company,DC=domain,DC=removed
Last time Group Policy was applied: 08/07/2017 at 13:11:32
Group Policy was applied from: DCName.domain.removed
Group Policy slow link threshold: 500 kbps
Domain Name: DomainRemoved
Domain Type: Windows 2008 or later
Applied Group Policy Objects
-----------------------------
Internet Connection & Firewall Policy
BootCamp Fixes
Interactive Logon Policy
Fix Daylight Savings
Win10 Computer Policy
Computer Software Restrictions (AppLocker)
Apogee Printers
Temp Fix for Folder Redirection
Default Domain Policy
The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Whole School Software Win7
Filtering: Denied (WMI Filter)
WMI Filter: Apply to Windows 7 Only
Win 7 Computer Policy Extension
Filtering: Denied (WMI Filter)
WMI Filter: Apply to Windows 7 Only
Local Group Policy
Filtering: Not Applied (Empty)
Computer Policy
Filtering: Denied (WMI Filter)
WMI Filter: Apply to Windows 7 Only
The computer is a part of the following security groups
-------------------------------------------------------
BUILTIN\Administrators
Everyone
BUILTIN\Users
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
This Organization
F701$
Domain Computers
Authentication authority asserted identity
CERTSVC_DCOM_ACCESS
System Mandatory Level
Resultant Set Of Policies for Computer
---------------------------------------
Administrative Templates
------------------------
REMOVED EXCESS POLICIES TO SHORTEN
GPO: Win10 Computer Policy
Folder Id: Software\Policies\Microsoft\Windows\NetCache\NoMakeAvailableOffline
Value: 1, 0, 0, 0
State: Enabled
GPO: Temp Fix for Folder Redirection
Folder Id: Software\Policies\Microsoft\Windows\Group Policy\{25537BA6-77A8-11D2-9B6C-0000F8080861}\NoSlowLink
Value: 1, 0, 0, 0
State: Enabled
GPO: Default Domain Policy
Folder Id: Software\Policies\Microsoft\Windows NT\CurrentVersion\Winlogon\SyncForegroundPolicy
Value: 1, 0, 0, 0
State: Enabled
GPO: Temp Fix for Folder Redirection
Folder Id: Software\Policies\Microsoft\Windows\Group Policy\{25537BA6-77A8-11D2-9B6C-0000F8080861}\NoGPOListChanges
Value: 0, 0, 0, 0
State: Enabled
USER SETTINGS
--------------
CN=Users Name,OU=Teaching Staff,OU=Staff,OU=Company,DC=domain,DC=removed
Last time Group Policy was applied: 08/07/2017 at 12:22:59
Group Policy was applied from: N/A
Group Policy slow link threshold: 500 kbps
Domain Name: DomainRemoved
Domain Type: Windows 2008 or later
Applied Group Policy Objects
-----------------------------
Internet Connection & Firewall Policy
Folder Redirection Policy
Smoothwall Staff Proxy Settings
Screensaver
Win10 Base User Policy
Win10 Staff Policy
Apogee Printers
Default Domain Policy
The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Staff
Filtering: Denied (WMI Filter)
WMI Filter: Apply to Windows 7 Only
Win 7 Staff Policy
Filtering: Denied (WMI Filter)
WMI Filter: Apply to Windows 7 Only
Local Group Policy
Filtering: Not Applied (Empty)
The user is a part of the following security groups
---------------------------------------------------
Domain Users
Everyone
BUILTIN\Users
NT AUTHORITY\INTERACTIVE
CONSOLE LOGON
NT AUTHORITY\Authenticated Users
This Organization
LOCAL
WiFi Access
PaperCut Welsh Bacc
PaperCut Welsh Bacc Adv
Staff
Smoothwall Staff
Admin Network Users
PaperCut Computing
HoD
CERTSVC_DCOM_ACCESS
Medium Mandatory Level
The user has the following security privileges
----------------------------------------------
Bypass traverse checking
Increase a process working set
Shut down the system
Remove computer from docking station
Resultant Set Of Policies for User
-----------------------------------
Administrative Templates
------------------------
REMOVED EXCESS POLICIES TO SHORTEN
Folder Redirection
------------------
N/A
我们正在迁移到虚拟服务器,但尚未移除旧 DC。因此,我们目前有 5 个混合操作系统的 DC:
2 个服务器 2016
1 个服务器 2012
2 个服务器 2008 R2
我们的森林和域功能级别目前都是 2008 R2。
我们的客户端电脑是 Windows 10 1607 64 位。
我已尝试提供尽可能多的信息,但如果您需要其他信息,请询问。
编辑:
未启用环回处理。RSoP.msc
未显示任何错误。gpresult
HTML 输出显示:文件夹重定向成功 703 毫秒