PC Review


Reply
Thread Tools Rate Thread

Associating Domain Account With Local User Profile

 
 
Will
Guest
Posts: n/a
 
      23rd May 2005
How can I force the association of a domain user account with a specific
local user profile? The domain account does not have any roaming profile.

--
Will
Internet: westes AT earthbroadcast.com



 
Reply With Quote
 
 
 
 
=?Utf-8?B?RWxlN2VO?=
Guest
Posts: n/a
 
      23rd May 2005
This can be done through the registry, but you will run into permissions
issues if you do not add permissions to the profile for the domain user
account. Here are the steps:

1. Add permissions to the local profile for the domain user account.
2. Make sure that the user has logged onto the machine with his/her domain
user account in the past (to create a profile). Login to the machine with a
local administrator account.
3. Open regedit and navigate to HKLM\Software\Microsoft\Windows
NT\CurrentVersion\ProfileList
4. In the profile list you will see a folder for every profile on the
machine. They are named with the SID of the user who owns the profile.
5. Find the profile that is associated with the local user account (look in
the ProfileImagePath value and you will see that it ends with the username of
the owner of the profile).
6. Copy the value of the ProfileImagePath for that profile (should look
like "%SystemDrive%\Documents and Settings\UserName"
7. Find the profile that is associated with the domain user account.
8 Open the ProfileImagePath for that profile and paste the path that was
copied in step 6.
9. Reboot the machine, and have the user logon with their domain account.
They will now be using the same profile whether they login with their local
account or their domain account.

WARNING!!! If you do not set permissions properly before the user logs in
with their domain account, you run the risk of losing the entire profile. If
this is on an XP machine, I recommend that you run the "Files and Settings
Transfer Wizard" to backup the profile before you attempt this.

"Will" wrote:

> How can I force the association of a domain user account with a specific
> local user profile? The domain account does not have any roaming profile.
>
> --
> Will
> Internet: westes AT earthbroadcast.com
>
>
>
>

 
Reply With Quote
 
Will
Guest
Posts: n/a
 
      24th May 2005
This was very helpful, but apparently your list is not complete.

For one thing, the user's %TEMP% environment variable is still set to use a
directory in the original profile.

For another thing, the user's Outlook and Outlook Express files are all
pointing to the values in the prior directory.

Just to step back a second, the reason for my request was that I lowered a
domain user from administrator on a box to users group. On the next login,
the domain user created a new profile instead of using the old one. I
found the security problem that was holding the user back, but by that point
it was too late. A new profile was being used, and the Outlook and Outlook
Express profiles were all lost and pointing to blank re-initialized ones.

This part of Microsoft's software could have used a little more testing.
It's a major pain.

--
Will
Internet: westes AT earthbroadcast.com


"Ele7eN" <(E-Mail Removed)> wrote in message
news:9A5EA8E3-E87E-4C54-BB6C-(E-Mail Removed)...
> This can be done through the registry, but you will run into permissions
> issues if you do not add permissions to the profile for the domain user
> account. Here are the steps:
>
> 1. Add permissions to the local profile for the domain user account.
> 2. Make sure that the user has logged onto the machine with his/her

domain
> user account in the past (to create a profile). Login to the machine with

a
> local administrator account.
> 3. Open regedit and navigate to HKLM\Software\Microsoft\Windows
> NT\CurrentVersion\ProfileList
> 4. In the profile list you will see a folder for every profile on the
> machine. They are named with the SID of the user who owns the profile.
> 5. Find the profile that is associated with the local user account (look

in
> the ProfileImagePath value and you will see that it ends with the username

of
> the owner of the profile).
> 6. Copy the value of the ProfileImagePath for that profile (should look
> like "%SystemDrive%\Documents and Settings\UserName"
> 7. Find the profile that is associated with the domain user account.
> 8 Open the ProfileImagePath for that profile and paste the path that was
> copied in step 6.
> 9. Reboot the machine, and have the user logon with their domain account.
> They will now be using the same profile whether they login with their

local
> account or their domain account.
>
> WARNING!!! If you do not set permissions properly before the user logs in
> with their domain account, you run the risk of losing the entire profile.

If
> this is on an XP machine, I recommend that you run the "Files and Settings
> Transfer Wizard" to backup the profile before you attempt this.
>
> "Will" wrote:
>
> > How can I force the association of a domain user account with a specific
> > local user profile? The domain account does not have any roaming

profile.
> >
> > --
> > Will
> > Internet: westes AT earthbroadcast.com
> >
> >
> >
> >



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
DOMAIN\user and LOCAL\user are same persons and want to share a profile on local machine. Chris Miller Windows XP Configuration 3 5th May 2010 03:15 AM
DOMAIN\user and LOCAL\user are same persons and want to share a profile on local machine. Chris Miller Windows XP Customization 3 5th May 2010 03:15 AM
How to Fix Phishing Filter After Converting Domain User Profile to Local User Profile? Will Windows XP Internet Explorer 1 15th Mar 2007 11:35 PM
How to Fix Phishing Filter After Converting Domain User Profile to Local User Profile? Will Windows XP Security 1 15th Mar 2007 11:35 PM
Creating Local Profile for Domain Account without the User Logging In Robert Mosher Windows XP Help 0 7th Apr 2004 08:11 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 07:10 PM.