D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Samba Active Directory

 

On 04/12/2019 08:17, Martin Gautier wrote:
> 
> Folder redirection is set in the GPO to \\SERVER\users\username as a 
> base with the client creating the necessary directories on login - using 
> the GPO editor's dropdown options.
> (that's a good point. I'll try changing that to specific defined folders 
> in the GPO and creating the necessary folders for the user on the server 
> today - setting the user's permissions using "smbcacls -C")

This bit is the key and why I mentioned that the domain users *must* 
have the relevant write permissions to create the necessary folder 
structure on the backend during the first auth/login - it's the bit that 
usually causes me headaches at least.

Have you double/triple checked the inheritance from the root of the 
profile folder as mentioned here:

https://wiki.samba.org/index.php/Roaming_Windows_User_Profiles

The section "Verify that permission inheritance is disabled on the root 
of the share. If any permission entry in the Advanced Security Settings 
window displays a path in the Inherited from column, click the Disable 
inheritance button" is really critical, they're not joking abut that.

On the bright side you're basically there at this point. I love that 
feeling when your test admin account is working perfectly but your 
general production users aren't for some reason and because you've 
fiddled with so many things on the admin account you're no longer quite 
sure what's different and which of the things you tweaked was the 
answer. Good times!
-- 
The Mailing List for the Devon & Cornwall LUG
https://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq