Add permissions for a usergroup to all domainprofiles (roaming profiles) on server 2008 R2Roaming Profiles LogRoaming user profile issues on Server 2008Server 2008 Roaming Profiles PermissionsWindows Server 2008 R2 Roaming ProfilesWindows 2008 R2 Roaming Profiles SetupRoaming Profiles - Win 7 & SBS 2011How Do I separate Windows 7 Roaming Profiles from Remote Desktop Services Profiles?Child Folder inheriting a permission that parent folder does not have (NTFS)Server 2012 R2. Add permissions to all folders and subfolders when inheritence is disabledHow to configure ACLs for roaming profiles and redirected folder in AGDLP context

The significance of kelvin as a unit of absolute temperature

What would be the way to say "just saying" in German? (Not the literal translation)

Does putting salt first make it easier for attacker to bruteforce the hash?

If someone intimidates another person, does the person affected gain the Frightened condition?

Convert only certain words to lowercase

How (un)safe is it to ride barefoot?

Could a person damage a jet airliner - from the outside - with their bare hands?

How to write a convincing religious myth?

What is the Leave No Trace way to dispose of coffee grounds?

Generate certain list from two lists

Why isn't Bash trap working if output is redirected to stdout?

A Salute to Poetry

How was the airlock installed on the Space Shuttle mid deck?

How far would a landing Airbus A380 go until it stops with no brakes?

Assigning function to function pointer, const argument correctness?

How to get depth and other lengths of a font?

Is it safe to remove Python 2.7.15rc1 from Ubuntu 18.04?

Is Dumbledore a human lie detector?

Command of files and size

How can powerful telekinesis avoid violating Newton's 3rd Law?

Can there be absolute velocity?

How many sets of dice do I need for D&D?

noalign caused by multirow and colors

The origin of the Russian proverb about two hares



Add permissions for a usergroup to all domainprofiles (roaming profiles) on server 2008 R2


Roaming Profiles LogRoaming user profile issues on Server 2008Server 2008 Roaming Profiles PermissionsWindows Server 2008 R2 Roaming ProfilesWindows 2008 R2 Roaming Profiles SetupRoaming Profiles - Win 7 & SBS 2011How Do I separate Windows 7 Roaming Profiles from Remote Desktop Services Profiles?Child Folder inheriting a permission that parent folder does not have (NTFS)Server 2012 R2. Add permissions to all folders and subfolders when inheritence is disabledHow to configure ACLs for roaming profiles and redirected folder in AGDLP context






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








1















This is our current situation: We have an active directory with Server 2008 R2 and roaming profiles which is currently in use (old server), and we have a new Server 2008 R2. We already set up a new AD on the new server and only want to copy the users files from the old to the new AD. (We have about 20 users, thus we can copy the old files to the new profile folders by hand.)



The new server is a hosted server, and our admin-user(-group) is not in the builtin Administrators group. To copy the users files to the new profile folders, we need to access the latter.



The problem is, windows server 2008 R2 only adds the builtin Administrators group to a profile folders ACL. Even if we add our admin-users-group to the root-profile-folder (with "This folder, subfolders and files"), the profile folders do not inherit this setting. We can take ownership of each profile folder, but this does not seem to be the right way.



So how can we add out admin-user-group to each profile folders ACL?










share|improve this question




























    1















    This is our current situation: We have an active directory with Server 2008 R2 and roaming profiles which is currently in use (old server), and we have a new Server 2008 R2. We already set up a new AD on the new server and only want to copy the users files from the old to the new AD. (We have about 20 users, thus we can copy the old files to the new profile folders by hand.)



    The new server is a hosted server, and our admin-user(-group) is not in the builtin Administrators group. To copy the users files to the new profile folders, we need to access the latter.



    The problem is, windows server 2008 R2 only adds the builtin Administrators group to a profile folders ACL. Even if we add our admin-users-group to the root-profile-folder (with "This folder, subfolders and files"), the profile folders do not inherit this setting. We can take ownership of each profile folder, but this does not seem to be the right way.



    So how can we add out admin-user-group to each profile folders ACL?










    share|improve this question
























      1












      1








      1








      This is our current situation: We have an active directory with Server 2008 R2 and roaming profiles which is currently in use (old server), and we have a new Server 2008 R2. We already set up a new AD on the new server and only want to copy the users files from the old to the new AD. (We have about 20 users, thus we can copy the old files to the new profile folders by hand.)



      The new server is a hosted server, and our admin-user(-group) is not in the builtin Administrators group. To copy the users files to the new profile folders, we need to access the latter.



      The problem is, windows server 2008 R2 only adds the builtin Administrators group to a profile folders ACL. Even if we add our admin-users-group to the root-profile-folder (with "This folder, subfolders and files"), the profile folders do not inherit this setting. We can take ownership of each profile folder, but this does not seem to be the right way.



      So how can we add out admin-user-group to each profile folders ACL?










      share|improve this question














      This is our current situation: We have an active directory with Server 2008 R2 and roaming profiles which is currently in use (old server), and we have a new Server 2008 R2. We already set up a new AD on the new server and only want to copy the users files from the old to the new AD. (We have about 20 users, thus we can copy the old files to the new profile folders by hand.)



      The new server is a hosted server, and our admin-user(-group) is not in the builtin Administrators group. To copy the users files to the new profile folders, we need to access the latter.



      The problem is, windows server 2008 R2 only adds the builtin Administrators group to a profile folders ACL. Even if we add our admin-users-group to the root-profile-folder (with "This folder, subfolders and files"), the profile folders do not inherit this setting. We can take ownership of each profile folder, but this does not seem to be the right way.



      So how can we add out admin-user-group to each profile folders ACL?







      windows-server-2008 active-directory permissions user-management roaming-profile






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Apr 11 '12 at 13:20









      x-rayx-ray

      11614




      11614




















          2 Answers
          2






          active

          oldest

          votes


















          0














          First of all, please make sure the policy "Allow Administrator group to Roaming Profiles" is applied to client pc, run "gpupdate /force" or restart the clients pc.



          This article explains how to set that policy (make sure it is set on your OU with your computers in.)



          The way I would transfer your profiles to your new server is to : log onto a client pc so the current profile is loaded, then change the profile patch in Active Directory to the location on your new server. (while the user is logged on) now when the user logs off the profile should copy from the client to your new server.



          This will only work if the computers and servers are on the same domain.






          share|improve this answer























          • For clarification: The Group Policy setting to add the Administrators group to the roaming profile folder permissions affects new profile folders as they're created. It does not affect existing profile folders.

            – joeqwerty
            Apr 11 '12 at 13:51











          • Our old and our new server are not on the same domain. Additionaly, the administrator user we got from the new servers hoster is not in the builtin administrator group.

            – x-ray
            Apr 11 '12 at 14:21


















          0














          The way to go is doing what you suspect not to be the right way. It also is the only way.



          You need to set permissions on each profile directory individually (since inheritance from the parent directory typically is not enabled). To do that it may be necessary to take ownership of all profile directories including all files and subdirectories.



          Since you have only 20 users it might not be worthwhile to automate the task. If you still want to do it, have a look at my free tool SetACL.



          Changing ownership and permissions on a larger number of directories can be very tedious in Explorer. SetACL Studio makes that work much easier.






          share|improve this answer























            Your Answer








            StackExchange.ready(function()
            var channelOptions =
            tags: "".split(" "),
            id: "2"
            ;
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function()
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled)
            StackExchange.using("snippets", function()
            createEditor();
            );

            else
            createEditor();

            );

            function createEditor()
            StackExchange.prepareEditor(
            heartbeatType: 'answer',
            autoActivateHeartbeat: false,
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader:
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            ,
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            );



            );













            draft saved

            draft discarded


















            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f378468%2fadd-permissions-for-a-usergroup-to-all-domainprofiles-roaming-profiles-on-serv%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown

























            2 Answers
            2






            active

            oldest

            votes








            2 Answers
            2






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes









            0














            First of all, please make sure the policy "Allow Administrator group to Roaming Profiles" is applied to client pc, run "gpupdate /force" or restart the clients pc.



            This article explains how to set that policy (make sure it is set on your OU with your computers in.)



            The way I would transfer your profiles to your new server is to : log onto a client pc so the current profile is loaded, then change the profile patch in Active Directory to the location on your new server. (while the user is logged on) now when the user logs off the profile should copy from the client to your new server.



            This will only work if the computers and servers are on the same domain.






            share|improve this answer























            • For clarification: The Group Policy setting to add the Administrators group to the roaming profile folder permissions affects new profile folders as they're created. It does not affect existing profile folders.

              – joeqwerty
              Apr 11 '12 at 13:51











            • Our old and our new server are not on the same domain. Additionaly, the administrator user we got from the new servers hoster is not in the builtin administrator group.

              – x-ray
              Apr 11 '12 at 14:21















            0














            First of all, please make sure the policy "Allow Administrator group to Roaming Profiles" is applied to client pc, run "gpupdate /force" or restart the clients pc.



            This article explains how to set that policy (make sure it is set on your OU with your computers in.)



            The way I would transfer your profiles to your new server is to : log onto a client pc so the current profile is loaded, then change the profile patch in Active Directory to the location on your new server. (while the user is logged on) now when the user logs off the profile should copy from the client to your new server.



            This will only work if the computers and servers are on the same domain.






            share|improve this answer























            • For clarification: The Group Policy setting to add the Administrators group to the roaming profile folder permissions affects new profile folders as they're created. It does not affect existing profile folders.

              – joeqwerty
              Apr 11 '12 at 13:51











            • Our old and our new server are not on the same domain. Additionaly, the administrator user we got from the new servers hoster is not in the builtin administrator group.

              – x-ray
              Apr 11 '12 at 14:21













            0












            0








            0







            First of all, please make sure the policy "Allow Administrator group to Roaming Profiles" is applied to client pc, run "gpupdate /force" or restart the clients pc.



            This article explains how to set that policy (make sure it is set on your OU with your computers in.)



            The way I would transfer your profiles to your new server is to : log onto a client pc so the current profile is loaded, then change the profile patch in Active Directory to the location on your new server. (while the user is logged on) now when the user logs off the profile should copy from the client to your new server.



            This will only work if the computers and servers are on the same domain.






            share|improve this answer













            First of all, please make sure the policy "Allow Administrator group to Roaming Profiles" is applied to client pc, run "gpupdate /force" or restart the clients pc.



            This article explains how to set that policy (make sure it is set on your OU with your computers in.)



            The way I would transfer your profiles to your new server is to : log onto a client pc so the current profile is loaded, then change the profile patch in Active Directory to the location on your new server. (while the user is logged on) now when the user logs off the profile should copy from the client to your new server.



            This will only work if the computers and servers are on the same domain.







            share|improve this answer












            share|improve this answer



            share|improve this answer










            answered Apr 11 '12 at 13:43









            SteveSteve

            1784




            1784












            • For clarification: The Group Policy setting to add the Administrators group to the roaming profile folder permissions affects new profile folders as they're created. It does not affect existing profile folders.

              – joeqwerty
              Apr 11 '12 at 13:51











            • Our old and our new server are not on the same domain. Additionaly, the administrator user we got from the new servers hoster is not in the builtin administrator group.

              – x-ray
              Apr 11 '12 at 14:21

















            • For clarification: The Group Policy setting to add the Administrators group to the roaming profile folder permissions affects new profile folders as they're created. It does not affect existing profile folders.

              – joeqwerty
              Apr 11 '12 at 13:51











            • Our old and our new server are not on the same domain. Additionaly, the administrator user we got from the new servers hoster is not in the builtin administrator group.

              – x-ray
              Apr 11 '12 at 14:21
















            For clarification: The Group Policy setting to add the Administrators group to the roaming profile folder permissions affects new profile folders as they're created. It does not affect existing profile folders.

            – joeqwerty
            Apr 11 '12 at 13:51





            For clarification: The Group Policy setting to add the Administrators group to the roaming profile folder permissions affects new profile folders as they're created. It does not affect existing profile folders.

            – joeqwerty
            Apr 11 '12 at 13:51













            Our old and our new server are not on the same domain. Additionaly, the administrator user we got from the new servers hoster is not in the builtin administrator group.

            – x-ray
            Apr 11 '12 at 14:21





            Our old and our new server are not on the same domain. Additionaly, the administrator user we got from the new servers hoster is not in the builtin administrator group.

            – x-ray
            Apr 11 '12 at 14:21













            0














            The way to go is doing what you suspect not to be the right way. It also is the only way.



            You need to set permissions on each profile directory individually (since inheritance from the parent directory typically is not enabled). To do that it may be necessary to take ownership of all profile directories including all files and subdirectories.



            Since you have only 20 users it might not be worthwhile to automate the task. If you still want to do it, have a look at my free tool SetACL.



            Changing ownership and permissions on a larger number of directories can be very tedious in Explorer. SetACL Studio makes that work much easier.






            share|improve this answer



























              0














              The way to go is doing what you suspect not to be the right way. It also is the only way.



              You need to set permissions on each profile directory individually (since inheritance from the parent directory typically is not enabled). To do that it may be necessary to take ownership of all profile directories including all files and subdirectories.



              Since you have only 20 users it might not be worthwhile to automate the task. If you still want to do it, have a look at my free tool SetACL.



              Changing ownership and permissions on a larger number of directories can be very tedious in Explorer. SetACL Studio makes that work much easier.






              share|improve this answer

























                0












                0








                0







                The way to go is doing what you suspect not to be the right way. It also is the only way.



                You need to set permissions on each profile directory individually (since inheritance from the parent directory typically is not enabled). To do that it may be necessary to take ownership of all profile directories including all files and subdirectories.



                Since you have only 20 users it might not be worthwhile to automate the task. If you still want to do it, have a look at my free tool SetACL.



                Changing ownership and permissions on a larger number of directories can be very tedious in Explorer. SetACL Studio makes that work much easier.






                share|improve this answer













                The way to go is doing what you suspect not to be the right way. It also is the only way.



                You need to set permissions on each profile directory individually (since inheritance from the parent directory typically is not enabled). To do that it may be necessary to take ownership of all profile directories including all files and subdirectories.



                Since you have only 20 users it might not be worthwhile to automate the task. If you still want to do it, have a look at my free tool SetACL.



                Changing ownership and permissions on a larger number of directories can be very tedious in Explorer. SetACL Studio makes that work much easier.







                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered Apr 12 '12 at 13:45









                Helge KleinHelge Klein

                1,79911318




                1,79911318



























                    draft saved

                    draft discarded
















































                    Thanks for contributing an answer to Server Fault!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid


                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.

                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function ()
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f378468%2fadd-permissions-for-a-usergroup-to-all-domainprofiles-roaming-profiles-on-serv%23new-answer', 'question_page');

                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

                    Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

                    Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020