Windows 10: Issue locking down Windows 10 Pro via Mandatory Network Profile & GPO

Discus and support Issue locking down Windows 10 Pro via Mandatory Network Profile & GPO in Windows 10 Customization to solve the problem; I've been trying to lock down some network Windows 10 Pro machines via Mandatory Network Profile & GPO. When I apply StartMenu and Taskbar... Discussion in 'Windows 10 Customization' started by LibraryITGirl, Mar 22, 2021.

  1. Issue locking down Windows 10 Pro via Mandatory Network Profile & GPO


    I've been trying to lock down some network Windows 10 Pro machines via Mandatory Network Profile & GPO. When I apply StartMenu and Taskbar restrictions, force the gpupdate/restart and log in to the machines I'm getting a Critical Error on the Start button. I disable the policy, force the gpupdate/restart and log in the error is gone. Can't seem to narrow down which GPO or combination of GPOs is breaking it. Any suggestions?

    :)
     
    LibraryITGirl, Mar 22, 2021
    #1

  2. Mandatory Profile with Window 10 Pro

    Has anyone successfully got mandatory profiles working with Windows 10 (currently running Win10 Pro 1511). My Start Menu and Search option does not work with Mandatory profile.

    Please help me on this issue. It's really an urgent.
     
    DharmendraBhandari, Mar 22, 2021
    #2
  3. johnpaul Win User
    Mandatory Profile (.v5)


    Hi
    Has anyone successfully got mandatory profiles working with Windows 10 (currently running Win10 Enterprise 1511).

    Essentially, I have it 99% of the way there, but whilst the start bar is clickable (which it previously wasn't), it now shows a blank start menu - ignoring either the Mandatory Profile Start Menu, or the XML Start Menu imported via Group Policy.

    My steps are based on having a dedicated "mandatory" local account to do all user customisations before copying it up to the netlogon share rather than using the default profile - which works fine but has none of our app customizations built in - unless I start look at importing reg keys etc;

    So here are my steps;

    Login to the gold image machine as .\mandatory
    1. Open Regedit
    2. Right Click on HKCU and give the following full permissions – logging in as a domain admin first
    a. Everyone
    b. All Application Pools
    c. Authenticated Users
    4. Close Regedit
    This is essentially instead of doing it via loading the hive - which seems to really help the start menu (I think)

    5. Reboot the machine
    6. Login as domain administrator – run Windows Enabler
    7. Copy the profile to \\%domaincontroller%\netlogon\profiles\.v5 with everyone as permissions
    8. Change a user to use that as their profile
    9. Reboot the computer (giving AD enough time to replicate)
    10. Login as that user
    11. Start Menu is clickable and edge works on the task bar

    However!.

    It does not pull in the start menu xml that we have configured, nor the start menu contained within the mandatory profile, but the start menu is fully clickable!

    I think other ways I have read on mandatory profiles about loading the hive from another machine didn't work because the DeviceAccess registry key seems to be permanantley locked even if I give everyone full permission - if I do it locally and then export the full mandatory profile it works.

    In anticipation

    John Paul
     
    johnpaul, Mar 22, 2021
    #3
  4. Boatvan Win User

    Issue locking down Windows 10 Pro via Mandatory Network Profile & GPO

    Windows 10 GPO Printer Add issues

    A total shot in the dark since this is a very specific issue to our environment, but here it goes...

    A little background on this issue, my school district is moving to windows 10. We partially deployed Windows 10 LTSB to some of the labs in the district. We are seeing sporadic issues with our Group Policies deploying printers. We have below 50% success rate with printers actually installing on the Windows 10 client machines.

    Thinking it was an issue with LTSB, we downloaded and installed Windows 10 Education version 1709 on a test VM and joined it to the domain. I then applied GPO’s from 4 different servers. 3 Physical Server 2012 R2 servers and the original problem Server 2012 R2 VM Server.

    What I found was the same inconsistency after rebooting the Win 10 Edu Test VM. I am getting the same Event 513. See below:


    Issue locking down Windows 10 Pro via Mandatory Network Profile & GPO print.png


    I am 100% sure the naming is right because I can manually add the same printer using the \\SERVER\FerLib path. All printers that fail to add have the Event 513. I am also going to post this on other forums.

    We are only seeing this on student accounts which are domain guest accounts, meaning their profiles are non-permanent. We do not have the option to turn them into regular users per district policy. If you need more info that I omitted please let me know. We are getting desperate.

    Thanks!
     
    Boatvan, Mar 22, 2021
    #4
Thema:

Issue locking down Windows 10 Pro via Mandatory Network Profile & GPO

Loading...
  1. Issue locking down Windows 10 Pro via Mandatory Network Profile & GPO - Similar Threads - Issue locking down

  2. Windows 10 Mandatory Profile no longer loading profile from the share

    in Windows 10 Gaming
    Windows 10 Mandatory Profile no longer loading profile from the share: When logging in using a mandatory profile none of the files from the share location profile copy locally. The profile has worked for years in Windows 10 and I just recently noticed it was no longer working correctly.Followed Microsoft's instructions for creating a mandatory...
  3. Windows 10 Mandatory Profile no longer loading profile from the share

    in Windows 10 Software and Apps
    Windows 10 Mandatory Profile no longer loading profile from the share: When logging in using a mandatory profile none of the files from the share location profile copy locally. The profile has worked for years in Windows 10 and I just recently noticed it was no longer working correctly.Followed Microsoft's instructions for creating a mandatory...
  4. Windows 10 Mandatory Profile no longer loading profile from the share

    in Windows 10 Customization
    Windows 10 Mandatory Profile no longer loading profile from the share: When logging in using a mandatory profile none of the files from the share location profile copy locally. The profile has worked for years in Windows 10 and I just recently noticed it was no longer working correctly.Followed Microsoft's instructions for creating a mandatory...
  5. Windows 10 Mandatory Profiles

    in Windows 10 Ask Insider
    Windows 10 Mandatory Profiles: Hi I have setup a demo of Azure Lab Services for my Windows 10 Image I need to lock this image down with mandatory profile, once all has been locked down, I need to ensure only 1 application is available - ie. Adobe CC Suite. So when my student users login to the RDP...
  6. How to create Mandatory User Profiles in Windows 10

    in Windows 10 News
    How to create Mandatory User Profiles in Windows 10: [ATTACH] [ATTACH]Many a time system admins need to create a pre-configured user account which works with fixed settings. These profiles are called mandatory user profiles (one of many Unique profiles) in Windows 10. In this guide, we will share how you [...] This post How to...
  7. What is mandatory profile

    in Windows 10 Customization
    What is mandatory profile: Hello, On windows 10, when you copy a profile 'exemple : default profile to C:\users\profile.v6 ' , there is a new select case 'mandatory profile' What does it mean ? what is the difference beteween older version and this, What's difference to rename ntuser.dat to...
  8. Windows 10 Mandatory Profile Path

    in User Accounts and Family Safety
    Windows 10 Mandatory Profile Path: Hello, Has anyone configured mandatory profiles for Windows 10 v1607? It works if I specify the mandatory path in the properties of the user account, but it does not work if I specify the path in Group Policy under computer configuration | System | User Profiles. . 77258
  9. Mandatory Profile (.v5)

    in User Accounts and Family Safety
    Mandatory Profile (.v5): Hi Has anyone successfully got mandatory profiles working with Windows 10 (currently running Win10 Enterprise 1511). Essentially, I have it 99% of the way there, but whilst the start bar is clickable (which it previously wasn't), it now shows a blank start menu - ignoring...
  10. Remove live tiles via GPO Win 10 Pro

    in Windows 10 Support
    Remove live tiles via GPO Win 10 Pro: Hello, I am stuck. I have created a customized start screen .xml with the export-startlayout command. I placed the file in a share, I configured the GPO to import that .xml file. When I log in, I get the two groups I specified, but, the two default live tile...