GPO not deleting mandatory roaming profiles - they show as local to system

Server 2012 R2 RDS deployment, all virtual, and 1 component shy of proper functionality. This is strictly for use with RemoteApp, and there are no hosted VDIs.

I'm reusing a known working mandatory profile, but they are not being deleted after users are logged off by the system. My investigation has come to the following state:

1. All user profiles from system/advanced properties are shown as 'Local'.

2. HKLM\..\ProfileList\<sid>\CentralProfile = the UNC path specified in my GPO (with .v2 appended)

3. HKLM\..\ProfileList\<sid>\State = 518  ? .. unknown. what state this profile is in.

4. DelProf2 sees all profiles as 'Roaming Profiles' and is able to programatically detect and delete roaming profiles.

Now... I could certainly do a simple triggered task on Security event 4647 to run DelProf /r  ... but

Any ideas on why system advanced properties is showing these profiles as local, and why the GPO option would be failing to remove them on logoff? Specifically, GPO settings are

- System/User Profiles/Delete cached copies of roaming profiles = Enabled

- Windows Components/Remote Desktop Services/Remote Desktop Session host/Profiles/Set path... = UNC path of profile

- Windows Components/Remote Desktop Services/Remote Desktop Session host/Profiles/Use Mandatory profiles... = Enabled

September 3rd, 2015 5:55pm

Hi,

Any ideas on why system advanced properties is showing these profiles as local, and why the GPO option would be failing to remove them on logoff?

Please run GPresult.exe to confirm that group policy settings are applied.

Gpresult

https://technet.microsoft.com/en-us/library/cc733160.aspx

Best Regards,

Amy

Free Windows Admin Tool Kit Click here and download it now
September 8th, 2015 11:25am

Hi Amy,

Yes, the policy is being applied, and I did just find the issue though. Reading through all applied policies, and I found a default security policy that had set "System\User Profiles\Only allow local user profiles" to enabled.

Thank you for your assistance. Disabling the local policy requirement for the hosts resolved this issue.

Kyle


September 9th, 2015 5:51pm

Hi Kyle,

Glad to hear that you have solved the issue!

Please feel free to let us know if there are any further requirements.

Best Regards,

Amy

Free Windows Admin Tool Kit Click here and download it now
September 9th, 2015 10:14pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics