Folder redirection is used to redirect the specified folder to the client computer to a particular location on the network.
For Folder Redirection to work properly, configure the
NTFS follows
1> Configure the folder to not inherit
permissions and remove all existing permissions.
2> Add the files local Administrator group with
full control of this folder, sub folder and files.
3> Add the domain admins domain security group
with full control of this folder, sub folder, and files
4> Add the system account with full control of
this folder, sub folder and files.
5> Add the creator/owner with full control of sub folder,
and files.
6> Add the authenticated users group with both
list folder/read data and create folders/append data – this everyone group as a
best practice
The
share permission of the folder can be configured to grant administrator full
control and authenticated users change permissions
To
redirect the documents folder to a network share, follow the steps given
below:-
- Log on to a designated window server 2008 administrative server.
- Click start/administrative tolls/Group Policy Management.
- Add the necessary domain to the GPMC as required.
- Expand the domain node to reveal the group policy objects container.
- Create a new GPO called User Folder Redirect GPO and open it for editing.
- After the user folder redirection GPO is opened for editing in the group policy management editor, expand the user configuration node ,expand policies, expand window settings ,and select the folder redirection node to display the user profiles folder that are available for redirection. If window 2000 ,window xp or windows server 2008 profiles required folder redirection, configure even the document folder will require additional testing and might not function correctly .For these operating system ,create a folder redirection GPO using the Window Server 2008 GPMC.
- In the setting pane, right-click the document folder and select properties.
- On the target tab ,click the setting drop-down list arrow , and select basic –redirect everyone’s folder to the same location, which reveals additional options based on group membership, but for this example ,select the basic redirection option.
- In the target folder location section, there are several options to choose from and should be reviewed for functionality; for this e.g., select create a folder for each user under the root path. This is very important if multiple folders will be redirected; more details are explained in the following steps.
- In the root path field, type in the sever and share name, for example \\server\\user profiles. Notice how the end-user name and document folder will be created below the root share folder. This require that the end user have at least change rights on the share permissions and they must also have create folder and create files NTFS permissions on the root folder that shared.
- At the top of the page, select the setting tab and unchecked the Grant the user Exclusive Rights to Documents check box .Leave the remaining check box unchanged.
- Click ok to complete the folder redirection configuration. A pop-up open that states that this policy will not display the folder redirection node if an administrator or user attempts to configure or view this group policy using policy management tools from window 2000, xp or window 2008. Click yes to accept this warning and configure the folder redirection.
- Back in the Group Policy Management Editor window, close the GPO.
- In the GPMC,link the user Folder Redirect GPO policy to an OU with a user account that can be used to test this policy .This user must log on to a window vista computer to allow proper processing of this policy.
- Log on to a window vista system with the test account.After the profile completes loading, click the start button, and locate and right –click the documents folder and then select properties .select the location tab and verify the path should be \\server\userprofile\XYZ\Documents.
- If the folder is not redirected properly, the window vista system might need to have a domain policy applied that forces synchronous foreground refresh of group polices. Also a very common configuration error is the NTFS and share permissions on the root folder.
- Each of the folder redirection folders will automatically be configured to be synchronized with the server and be available offline. When additional server folder needs to be configured to be available offline, follow the below steps:
1> Locate the shared network folder that should
be made available offline.
2> Right-click the folder and select always
available offline.
As
long as the server share allows offline synchronization and the client
workstation also supports this, as they both do by default, which is all that is
necessary.
Rahul Khadse
Posted in: