Blocking a Default Domain Profile for Administrator Accounts
was wondering if there was a way to block the use of a default domain profile for a certain Domain Administrator's account (or a group of Administrators). Our default domain profile is working perfectly, however when we complete a new Server 2008/R2 installation (for example) and log in with a domain account, the profile is generated from the copy on \\server\netlogon (as expected and designed). However some admins do not like their initial environment being 'controlled' in this way, although their profile is not locked down in any way and they are able to change the start menu shortcuts, background etc. I attempted to set Deny Permissions for a specific domain admin on the profile folder, and while this did prevent the default domain profile from being used, the OS did not 'default' back to using the local default profile as a template (as I had hoped), instead it created a temporary logon environment. Is there any other workaround? I would be nice to specify users and/or groups required to use the default domain profile via GPO (rather than every user in AD) but I can't seem to find a way to do that. Am I missing something? Even if I could limit its use to Windows 7 clients and not Server 2008, that would be helpful.
June 22nd, 2011 5:42pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics