Results 1 to 5 of 5

Configuring Folder Redirection in Windows Server 2008

This is a discussion on Configuring Folder Redirection in Windows Server 2008 within the Windows 2008 forums, part of the Operating systems category; Configuring Folder Redirection in Windows Server 2008 Folder redirection can be used to redirect certain special folders on the end ...

  1. #1
    Member
    Join Date
    Jan 2009
    Posts
    64

    Post Configuring Folder Redirection in Windows Server 2008

    Configuring Folder Redirection in Windows Server 2008



    Folder redirection can be used to redirect certain special folders on the end userís desktop to server shares. Special folders such as the My Documents or Documents, which is the default folder for users to store and access their data, can be redirected to server shares.

    The following are some basic rule-of-thumb guidelines when using this Group Policy extension:

    1) Allow the system to create the folders: If the folders are created by the administrator, they will not have the correct permissions. But properly configuring the share and NTFS permissions on the server share is essential in providing a functional folder redirection experience.

    2) Enable client-side caching or offline file synchronization: This is important for users with portable computers but is not the desired configuration for folder redirection on Terminal Servers. Furthermore, when storing data on end-user workstations, it is not desired or might violate regulatory and/or security requirements.

    3) Use fully qualified (UNC) paths or DFS paths for server share locations: For example, use \\Server1.companyabc.com\UserProfiles or \\companyabc.com\UserProfiles\ if DFS shares are deployed.

    Before folder redirection can be expected to work, share and NTFS (New Technology File System) permissions must be configured appropriately.

    For folder redirection to work properly, configure the NTFS as follows:

    1) Configure the folder to not inherit permissions and remove all existing permissions.
    2) Add the file serverís local Administrators group with Full Control of This Folder, Subfolders, and Files.
    3) Add the Domain Admins domain security group with Full Control of This Folder, Subfolders, and Files.
    4) Add the System account with Full Control of This Folder, Subfolders, and Files.
    5) Add the Creator/Owner with Full Control of Subfolders and Files.
    6) Add the Authenticated Users group with both List Folder/Read Data and Create Folders/Append Data Ė This Folder Only rights. The Authenticated Users group can be replaced with the desired group, but do not choose the Everyone group as a best practice.

    The share permissions of the folder can be configured to grant administrators Full Control and authenticated users Change permissions.

    To redirect the Documents folder to a network share, follow the steps given below:

    1. Log on to a designated Windows Server 2008 administrative server.
    2. Click Start and then All Programs and then Administrative Tools and then select Group Policy Management.
    3. Add the necessary domains to the GPMC as required.
    4. Expand the Domains node to reveal the Group Policy Objects container.
    5. Create a new GPO called UserFolderRedirectGPO and open it for editing.
    6. After the UserFolderRedirectGPO is opened for editing in the Group Policy Management Editor, expand the User Configuration node, expand Policies, expand Windows Settings, and select the Folder Redirection node to display the user profile folders that are available for redirection. If Windows 2000, Windows XP, or Windows Server 2003 profiles require folder redirection, configuring even the Documents folder will require additional testing and might not function correctly. For these operating systems, create a folder redirection GPO using the Windows Server 2003 GPMC.
    7. In the Settings pane, right-click the Document folder and select Properties.
    8. On the Target tab, click the Setting drop-down list arrow, and select Basic Ė Redirect Everyoneís Folder to the Same Location, which reveals additional options. There is another option to configure folder redirection to different locations based on group membership, but for this example, select the basic redirection option.
    9. In the Target Folder Location section, there are several options to choose from and should be reviewed for functionality; for this example, select Create a Folder for Each User Under the Root Path. This is very important if multiple folders will be redirected; more details are explained in the following steps.
    10. In Root Path field, type in the server and share name, for example \\Server\UserProfiles. Notice how the end-user name and Document folder will be created below the root share folder. This requires that the end users have at least Change rights on the share permissions and they must also have the Create Folder and Create File NTFS permissions on the root folder that is shared.
    11. At the top of the page, select the Settings tab and uncheck the Grant the User Exclusive Rights to Documents check box. Leave the remaining check boxes unchanged.
    12. Click OK to complete the folder redirection configuration. A pop-up opens that states that this policy will not display the Folder Redirection node if an administrator or user attempts to configure or view this group policy using policy management tools from Windows 2000, Windows XP, or Windows Server 2003. Click Yes to accept this warning and configure the folder redirection.
    13. Back in the Group Policy Management Editor window, close the GPO.
    14. In the GPMC, link the new UserFolderRedirectGPO policy to an OU with a user account that can be used to test this policy. This user must log on to a Windows Vista computer to allow proper processing of this policy.
    15. Log on to a Windows Vista system with the test user account. After the profile completes loading, click the Start button, and locate and right-click the Documents folder and then select Properties. Select the Location tab and verify the path. For example, for a user named XYZ, the path should be \\Server\UserProfiles\XYZ\Documents.

    If the folder is not redirected properly, the Windows Vista system might need to have a domain policy applied that forces Synchronous Foreground Refresh of group policies. Also a very common configuration error is the NTFS and share permissions on the root folder.

    Each of the folder redirection folders will automatically be configured to be synchronized with the server and be available offline. When additional server folders need to be configured to be available offline, follow the below steps:

    1. Locate the shared network folder that should be made available offline.
    2. Right-click the folder and select Always Available Offline


    As long as the server share allows offline synchronization and the client workstation also supports this, as they both do by default, which is all that is necessary.

  2. #2
    Junior Member
    Join Date
    May 2011
    Posts
    1

    Thumbs up Excelent post

    Thank you for this detailed guide. This works excelent for Windows XP too if you check "Also apply redirection policy to Windows 2000, Windows 2000 Server, Windows XP, and Windows Server 2003 operating systems" from step 11.
    Applying the specific permissions(first part of your guide) made a huge difference for me.

    thanks

  3. #3
    Junior Member
    Join Date
    Sep 2011
    Posts
    1

    Default

    I follow the instructions, removed inherited permissions, but the user ends up with the permissions for "This Folder Only", The user is the creator Owner,with full permissions, but can't write to my documents.
    Any Ideas why. deleted folders and redirect to different folder and same thing.
    Thak you your help.
    Luvi

  4. #4
    Junior Member
    Join Date
    Nov 2011
    Posts
    1

    Default Folder Redirection Question

    I'm the third admin to take over at my work. The first guy setup folder redirection and it worked well. The other guy came along some things got changed and we've been having to go though cleaning up stuff. I understand how to set permissions and create folder redirection. We are having some issues though.

    We have 14 sites in AD. Folder redirection is setup at the site level OU. Under that OU is an OU for users which pick up folder redirection from the site level OU. I've been here for a while, but now I've taken on the role of network admin and ever since I can remember folder redirection has been pointed to \\server name.domain name\share\user name\redirected folders\whatever folder so for my documents it would be \\server name.domain name\share\user name\redirected folders\my documents. I'm not sure how the redirected folder is placed there. It's my understanding and when ever I set up folder redirection it puts the folder in the user home directory....ex. \\server name.domain name\share\user name\my documents.

    On all, but two sites it's pointed to \\server name.domain name\share\user name\redirected folders\my documents or desktop or etc. On the other two sites it is \\server name.domain name\share\user name\my documents or desktop or etc.

    Am I missing something. In Group Policy for all 14 sites the folder redirection is set to basic....create folder for every user under root path and is pointed to \\server name\share. How did he get the redirected folder between user name and the acutal folder to redirect?

    Thanks for your help.
    Last edited by jmoney; 11-18-2011 at 02:49 AM.

  5. #5
    Junior Member
    Join Date
    Apr 2013
    Posts
    1

    Default

    Thank you Shaurya for such a well written and detailed howto. This helped me tremendously and I couldn't have done it without your guide! This is by far the best guide I've found on the web regarding folder redirection using GPO.

    Thanks again.

Similar Threads

  1. Multicast Addresses of Windows Server 2008
    By Azingo in forum Operating systems
    Replies: 0
    Last Post: 10-07-2008, 11:43 AM
  2. Slow-Link Processing of Windows Server 2008
    By Aptora in forum Operating systems
    Replies: 0
    Last Post: 10-07-2008, 11:12 AM
  3. Windows Server 2008 Services by Role
    By Encompass in forum Operating systems
    Replies: 0
    Last Post: 10-06-2008, 11:57 AM
  4. Enforcement Methods to Windows Server 2008
    By Cingular in forum Operating systems
    Replies: 0
    Last Post: 10-06-2008, 11:43 AM
  5. New Capabilities in Windows Server 2008
    By Cingular in forum Operating systems
    Replies: 0
    Last Post: 10-06-2008, 11:36 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •