VMware Horizon Community
GeoffTX
Contributor
Contributor
Jump to solution

Persona manager folder permissions and admin access

We're testing View 5 and person manager, and ran across an issue during the PoC.

Has anyone found a way to allow admin access to the user profile folders created by Persona Manager? By default, PM creates the user folders under the repository share with ownership exclusively set to the user, so as an admin, when I try to look at any of the files there I can't without taking ownership first. Not only is it a pain to have to do this for troubleshooting, I'm concerned that taking ownership will break things for the user going forward

With MS folder redirection there's a GPO option you can select to make the folder permissions non-exclusive. Any way to do the same thing with the folders and files persona manager is creating?

Thanks,


Geoff

0 Kudos
1 Solution

Accepted Solutions
mittim12
Immortal
Immortal
Jump to solution

Welcome to the forums.   Under the systems/users/profiles GPO there is an option to Add the Administrators security group to roaming user profiles

View solution in original post

0 Kudos
10 Replies
mittim12
Immortal
Immortal
Jump to solution

Welcome to the forums.   Under the systems/users/profiles GPO there is an option to Add the Administrators security group to roaming user profiles

0 Kudos
GeoffTX
Contributor
Contributor
Jump to solution

Thanks, that fixed it.

So now that I can see what PM is saving there I note that the appdata folders are being copied. I already have a GPO in place to redirect appdata (roaming), so should I be turning that off? Not sure why I'd want to copy the same data twice, but I do want local appdata and did enable that in the persona GPO.

0 Kudos
mittim12
Immortal
Immortal
Jump to solution

If you already have a working solution for app data then yes I would disable it.  Like you I see no need to copy it twice. 

0 Kudos
GeoffTX
Contributor
Contributor
Jump to solution

Thanks again. I did some more digging and discovered that while the folders themselves are duplicated the contents are not, so even though the PM folders for Local, Local Low and Roaming are all there, the Roaming folder (the one already redirected by Windows) contains much less than the one in the redirected share. So keeping them both enabled seems to make sense at this point. More testing to do...

Geoff

0 Kudos
gstrouth
Enthusiast
Enthusiast
Jump to solution

That does work but not for folder redirection, anyway around that?

0 Kudos
GeoffTX
Contributor
Contributor
Jump to solution

"That does work but not for folder redirection, anyway around that?"

If you're talking about the VMware folder redirection settings, I ended up using the MS folder redirection User Conifg GPO settings, not the ones in the VMware PM Compter Config. If you use the Windows GPO you can uncheck the "Grant exclusive use..." checkbox and then admins will have access to redirected folders. I'm still uncertain if using the VMware redirection GPO settings vs. the MS settings provides any additional functionality for PM, or if they included it as a convenience so you can set everything from one place. If it's the former we need more info; if the later then they need an additional "unexclusive" option (and the one to copy existing files too) like the MS settings provide.

Geoff

0 Kudos
gstrouth
Enthusiast
Enthusiast
Jump to solution

Using the VMware PM there are more folders that you can redirect vs the Microsoft ones. I agree there needs to be an option for the rights, I have submitted it as an enhancement request a while back so hopefully they do it.

0 Kudos
kpelt
Contributor
Contributor
Jump to solution

Any change to this?  And specifically speaking on the redirected docs, downloads, music, etc, not the Profiles. 

0 Kudos
gstrouth
Enthusiast
Enthusiast
Jump to solution

No

0 Kudos
kpelt
Contributor
Contributor
Jump to solution

Thanks for the reply.  I'll see what I can find out and report back.

0 Kudos