Windows 10: Windows domain Profile segregate

Discus and support Windows domain Profile segregate in Windows 10 Network and Sharing to solve the problem; Hi All,I have one query, actually I configured one desktop in our domain environment with 2 drive C & D Drive and on this computer multiple users using... Discussion in 'Windows 10 Network and Sharing' started by Tahir Q. Qureshi, Sep 14, 2023.

  1. Windows domain Profile segregate


    Hi All,I have one query, actually I configured one desktop in our domain environment with 2 drive C & D Drive and on this computer multiple users using on different shift time. every user's login in that computer so it will create user profile on the C drive. So, my requirement is if users are login on the computer, then they can access c as well as d drive data but if user 1 login on the computer so he will access only his data from c & d drive, but he cannot view user 2 data which saved in c as well as d drive on same computer that is my query.is there any way then we segregate the

    :)
     
    Tahir Q. Qureshi, Sep 14, 2023
    #1
  2. Kari Win User

    Migrate Locale Profile to Domain

    I removed my reply because watching those instructions on TechNet I started wondering if they really work with Windows 10.

    Anyway, whatever you try create first a dummy profile, customize it a bit and move it to domain. If everything works, you can then move real profiles.
     
  3. changari Win User
    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, Sep 14, 2023
    #3
  4. bdanmo Win User

    Windows domain Profile segregate

    UnattendedJoin error: failed to find the domain data (0x6e)

    Thanks for the suggestion! I don't want to add a domain account, as this is a generic unattended install that will be used for all company machines. Do you think it's possible that the computer would join the domain if, instead of using UnattendedJoin in specialize, I used your steps but left out the specific account?

    The other thing I was thinking was to use a generic account to allow the domain join during the specialize step. I added a machine password in the UnattendedJoin component, and instead of getting the error listed above, I got an authentication error, which makes me think I could probably do a secure join instead of the unsecure join.

    Thoughts?
     
    bdanmo, Sep 14, 2023
    #4
Thema:

Windows domain Profile segregate

Loading...
  1. Windows domain Profile segregate - Similar Threads - domain Profile segregate

  2. Temporary Profiles on a Domain

    in Windows 10 Gaming
    Temporary Profiles on a Domain: We are experiencing an increasing issue where users are logging into their computers with temporary profiles. Logging off and back on sometimes multiple times or restarting the computer resolves the issue for some users temporarily, but this has become a recurring problem.The...
  3. Temporary Profiles on a Domain

    in Windows 10 Software and Apps
    Temporary Profiles on a Domain: We are experiencing an increasing issue where users are logging into their computers with temporary profiles. Logging off and back on sometimes multiple times or restarting the computer resolves the issue for some users temporarily, but this has become a recurring problem.The...
  4. Windows domain Profile segregate

    in Windows 10 Gaming
    Windows domain Profile segregate: Hi All,I have one query, actually I configured one desktop in our domain environment with 2 drive C & D Drive and on this computer multiple users using on different shift time. every user's login in that computer so it will create user profile on the C drive. So, my...
  5. Windows domain Profile segregate

    in Windows 10 Software and Apps
    Windows domain Profile segregate: Hi All,I have one query, actually I configured one desktop in our domain environment with 2 drive C & D Drive and on this computer multiple users using on different shift time. every user's login in that computer so it will create user profile on the C drive. So, my...
  6. Migrate from domain profile to local profile

    in Windows 10 Gaming
    Migrate from domain profile to local profile: Here is my situation, I had a Windows server set up in my house with PCs connected to it on my network. I took the server out of operation a few years ago but have been logging into my PCs with the same accounts with no issues. A few days ago I wanted to change the password...
  7. Migrate from domain profile to local profile

    in Windows 10 Software and Apps
    Migrate from domain profile to local profile: Here is my situation, I had a Windows server set up in my house with PCs connected to it on my network. I took the server out of operation a few years ago but have been logging into my PCs with the same accounts with no issues. A few days ago I wanted to change the password...
  8. One profile for Domain and non-domain

    in Windows 10 Network and Sharing
    One profile for Domain and non-domain: I have a couple users that work on their laptops outside of the office but need to connect to the domain when here. When they connect it creates a new profile and they have to re-register their software licenses. They also lose access to all of their documents and such unless...
  9. Windows 10 Firewall logging on domain profile.

    in AntiVirus, Firewalls and System Security
    Windows 10 Firewall logging on domain profile.: I am working on turning on the domain profile for Windows 10 via gpo. We have a relatively large environment and this has not been turned on for the domain profile in the past. So the current plan is turn on the Firewall with Policy and create an Any/Any rule for inbound...
  10. Migrate Locale Profile to Domain

    in User Accounts and Family Safety
    Migrate Locale Profile to Domain: Hi Everyone, Does anyone know how to migrate a local profile to a domain profile without software? I have some Windows 10 computers that are setup as workgroups, but we need to move them to the company domain. I want to ensure that users don't lose their files, settings,...