Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Here is the scenario:
1) Install windows on a new system. Join to
the domain, use the domain administrator
account to install applications, get GP
settings to have WSUS update the system
(we also have my documents redirected)2) Run sysprep with -mini and -reseal
3) capture image
4) push image back down to another system
5) Upon logging into the freshly imaged
machine as a regular domain user the only
previous known location of 'My Documents'
was the network location belonging to the
domain administrator account, and as such
cannot be touched/redirected by the regular
domain user.
Is this an issue of having a domain
configuration that WDS can't handle or am I
setting up improper file permission/GPO
configuration on the local machine before
sysprepping/imaging?
My only thought is to complete step 1 from
above but then take the system out of the
domain and delete all domain profiles before
running sysprep.
Since the folder redirection happens by GP,
the location of the redirected folder cannot be
changed to a local folder with user accessible
permissions before running sysprep.
UPDATE:
Using an image from a system that has NOT
been joined to the domain also causes grief
with our folder redirection.
When pulling down the image, booting the
machine and then joining it to the domain
causes My Documents to not want to be
synchronized properly due to a time-out
looking for the domain controller.
Getting around this by disabling the "Media
Sense" feature of XP then brings about more
problems which I have yet to remedy,
specifically any files located on the local "My
Documents" location (desktop.ini, My
Pictures, etc) will cause an "Invalid Security
Descriptor" ID.
Again, do these sound like an incorrectly
configured domain or just growing pains in the
WDS system?

I too have had a lot of grief when pushing an image of an already joined computer over to another. Logic says there obviously doesn't exist a computer account in AD for the new computer, hence no trust is created. You need to "rejoin" so to speak. Every new computer needs to be joined to the domain, but after they're once joined you can do an image backup of that computer if you like. I use Acronis to create a secure zone image backup locally, but an even better solution would be to store it on the network (Acronis can do that, I just don't have the space).
When it comes to the sync with the relocated 'My Documents' folder, my experience says the best way of relocating it is through GPO (folder redirection). Is that the way you did it?
Another possible cause could be slow communication, I've had that problem a couple of times when the server hardware is slow or faulty. We actually had that problem at our own office once, after the server had been overheated a couple of times. We bought a new one when we moved to a place where heat is not an issue and haven't had a problem since. Just an idea.

![]() |
Win 2k3 Server Roaming Pr...
|
Help for DOS Command to r...
|
| Login or Register to Reply | |
| Login | Register |
| Ads by Google |