<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://share.intelliem.com/cs/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Dan Holme - All Comments</title><link>http://share.intelliem.com/cs/blogs/danholme/default.aspx</link><description /><dc:language>en</dc:language><generator>CommunityServer 2008 (Build: 30417.1769)</generator><item><title>What a difference three years makes: SharePoint 2010 revealed beta club</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2009/10/19/what-a-difference-three-years-makes-sharepoint-2010-revealed.aspx#3836</link><pubDate>Mon, 19 Oct 2009 21:10:52 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:3836</guid><dc:creator>What a difference three years makes: SharePoint 2010 revealed beta club</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;What a difference three years makes: SharePoint 2010 revealed beta club&lt;/p&gt;
&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=3836" width="1" height="1"&gt;</description></item><item><title>Redirect Favorites Folder for XP using Windows 2008 GPO or SBS2008</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2008/06/06/group-policy-preferences-rock.aspx#3834</link><pubDate>Thu, 08 Oct 2009 23:09:28 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:3834</guid><dc:creator>Computer Troubleshooters</dc:creator><description>&lt;p&gt;Redirect Favorites Folder for XP using Windows 2008 GPO or SBS2008&lt;/p&gt;
&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=3834" width="1" height="1"&gt;</description></item><item><title>re: User Data &amp; Settings (Connections 2008)</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2008/04/30/user-data-amp-settings-connections-2008.aspx#1730</link><pubDate>Mon, 02 Mar 2009 13:10:29 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:1730</guid><dc:creator>typeoneg</dc:creator><description>&lt;p&gt;Hey Dan,&lt;/p&gt;
&lt;p&gt;Thx for the response.&lt;/p&gt;
&lt;p&gt;I have checked in the registry for those settings. Here is an example for PERSONAL: \\ei-ie.local\usersei\testmc\Documents&lt;/p&gt;
&lt;p&gt;The security settings are all ok to me.&lt;/p&gt;
&lt;p&gt;Can I maybe upload some pictures of these settings to u?&lt;/p&gt;
&lt;p&gt;Wim&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=1730" width="1" height="1"&gt;</description></item><item><title>re: User Data &amp; Settings (Connections 2008)</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2008/04/30/user-data-amp-settings-connections-2008.aspx#1725</link><pubDate>Mon, 02 Mar 2009 05:50:22 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:1725</guid><dc:creator>danholme</dc:creator><description>&lt;p&gt;Hello, Greets!&lt;/p&gt;
&lt;p&gt;I&amp;#39;m not sure what could be going wrong for you... It definitely &amp;quot;works as advertised&amp;quot; . &amp;nbsp;Please go to one of your clients that you&amp;#39;ve configured, go to REGEDIT, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserShellFolders and look at the values there for PERSONAL (which is &amp;quot;documents&amp;#39;), DESKTOP &amp;amp; FAVORITES. &amp;nbsp;Do they really look right to you? &amp;nbsp;Are the permissions correct?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=1725" width="1" height="1"&gt;</description></item><item><title>re: User Data &amp; Settings (Connections 2008)</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2008/04/30/user-data-amp-settings-connections-2008.aspx#1675</link><pubDate>Fri, 27 Feb 2009 16:09:33 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:1675</guid><dc:creator>typeoneg</dc:creator><description>&lt;p&gt;Hey Dan,&lt;/p&gt;
&lt;p&gt;I have recently implemented your solution for roaming profiles and offline files with the usage of redirection.&lt;/p&gt;
&lt;p&gt;But i have some problems now.&lt;/p&gt;
&lt;p&gt;In vista explorer all the special icons of the folders desktop, documents, favourites, music, pictures and videos.&lt;/p&gt;
&lt;p&gt;(All the folders for which i have created a dfs share.) These folders are just showing as a yellow folder with a shortcut icon.&lt;/p&gt;
&lt;p&gt;Also the favourites links are not working.&lt;/p&gt;
&lt;p&gt;Is there something which i could i have done wrong?&lt;/p&gt;
&lt;p&gt;I followed all of your instructions like u explained in your book.&lt;/p&gt;
&lt;p&gt;Great if you would give me helping hand here.&lt;/p&gt;
&lt;p&gt;Greets&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=1675" width="1" height="1"&gt;</description></item><item><title>BPSPC: Nuts and Bolts Governance - Practical Application of the Concepts with Dan Holme</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2009/02/02/spbc-feb-09-slides.aspx#284</link><pubDate>Tue, 03 Feb 2009 08:12:43 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:284</guid><dc:creator>The Bamboo Team Blog</dc:creator><description>&lt;p&gt;Dan Holme, Director of Training &amp;amp; Consulting for Intellium , is a SharePoint MVP with a particular&lt;/p&gt;
&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=284" width="1" height="1"&gt;</description></item><item><title>re: User Data &amp; Settings: New DFS recommendations</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2008/06/06/user-data-amp-settings-new-dfs-recommendations.aspx#232</link><pubDate>Tue, 20 Jan 2009 01:32:51 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:232</guid><dc:creator>paulbrod</dc:creator><description>&lt;p&gt;Another update about csccmd.exe &amp;amp; pinning &amp;quot;Offline Files&amp;quot;, there&amp;#39;s a good article on &amp;quot;Offline Files&amp;quot; at:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://windowsteamblog.com/blogs/windowsvista/archive/2007/01/29/working-with-offline-files.aspx"&gt;windowsteamblog.com/.../working-with-offline-files.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Here (page 2) Brian Aust (MS) mentions that csccmd is not supported or compatible on Vista, though a Offline Files API is available to both C/C++ programming via COM objects and interfaces. &amp;nbsp;Brian also says here &amp;quot;As for excluding a sub folder from being made avialable offline (i.e. pinned), that ability was removed in Vista.&amp;quot;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=232" width="1" height="1"&gt;</description></item><item><title>Event Viewer System Log Error 13 | keyongtech</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2008/08/18/event-log-error.aspx#218</link><pubDate>Sun, 18 Jan 2009 17:43:36 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:218</guid><dc:creator>Event Viewer System Log Error 13 | keyongtech</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Event Viewer System Log Error 13 | keyongtech&lt;/p&gt;
&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=218" width="1" height="1"&gt;</description></item><item><title>listare gruppi cui un utente appartiene | hilpers</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2008/02/27/fully-enumerating-a-user-s-group-membership-part-i.aspx#217</link><pubDate>Sun, 18 Jan 2009 13:50:55 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:217</guid><dc:creator>listare gruppi cui un utente appartiene | hilpers</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;listare gruppi cui un utente appartiene | hilpers&lt;/p&gt;
&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=217" width="1" height="1"&gt;</description></item><item><title>re: Connections 2008 Presentations And Tools</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2008/11/13/connections-2008-presentations-and-tools.aspx#162</link><pubDate>Mon, 15 Dec 2008 20:40:54 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:162</guid><dc:creator>curacaojay</dc:creator><description>&lt;p&gt;Any tools yet Dan?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=162" width="1" height="1"&gt;</description></item><item><title>re: User Data &amp; Settings: New DFS recommendations</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2008/06/06/user-data-amp-settings-new-dfs-recommendations.aspx#161</link><pubDate>Thu, 11 Dec 2008 04:08:51 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:161</guid><dc:creator>paulbrod</dc:creator><description>&lt;p&gt;I&amp;#39;d like to post some further information about some issues we&amp;#39;ve been experiencing and resolved. &amp;nbsp;The issues were to do with the DFS folders being created in all lowercase and plain/blank folder icons being displayed in Windows Vista.&lt;/p&gt;
&lt;p&gt;Refer to the following two articles for details:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://forums.microsoft.com/TechNet/ShowPost.aspx?PostID=4233836&amp;amp;SiteID=17&amp;amp;mode=1"&gt;forums.microsoft.com/.../ShowPost.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="https://blogs.technet.com/filecab/archive/2008/09/23/storage-tips-how-to-create-namespace-links-in-uppercase.aspx"&gt;blogs.technet.com/.../storage-tips-how-to-create-namespace-links-in-uppercase.aspx&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=161" width="1" height="1"&gt;</description></item><item><title>re: User Data &amp; Settings: New DFS recommendations</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2008/06/06/user-data-amp-settings-new-dfs-recommendations.aspx#157</link><pubDate>Thu, 04 Dec 2008 03:29:33 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:157</guid><dc:creator>paulbrod</dc:creator><description>&lt;p&gt;Hey Dan,&lt;/p&gt;
&lt;p&gt;You&amp;#39;re welcome, yes UDS is a beast but it is gradually being tamed ;)&lt;/p&gt;
&lt;p&gt;We have found that the user does indeed need require READ on the %username% physical namespace folder, even with Bypass traverse checking enabled on the server.&lt;/p&gt;
&lt;p&gt;We have also found the &amp;quot;Modify&amp;quot; (M) permissions were sufficient, however these permssions, we discovered, also permits the user to delete their Document, Desktop and Profiles folders when the (M) permission is set at those levels in the physical namespace. &lt;/p&gt;
&lt;p&gt;I have determined that the modify permission actually equates to (X,RD,RA,REA,WD,AD,WA,WEA,DC,D,RC), when viewing permissions through the GUI. &amp;nbsp;The D or Delete permission at the Document, Desktop &amp;amp; Profiles folders actually allows the user to delete these parent folders. &amp;nbsp;So we are now using (X,RD,RA,REA,WD,AD,WA,WEA,DC,RC), basically (M) without the (D) and this works just fine and the user now cannot delete the parent folders. &amp;nbsp;There is a catch though, when using icalcs to implement this set of permissions it has to be done using (RX,W,DC) or else there&amp;#39;s issues. &amp;nbsp;So in summary (RX,W,DC) = (X,RD,RA,REA,WD,AD,WA,WEA,DC,RC), when viewed through the GUI but use (RX,W,DC) when implementing this through icacls!!! Weird but works!!!&lt;/p&gt;
&lt;p&gt;Additionally, we had issues with the XP SP3 version of fdeploy.dll (Folder Redirection CSE) and are now running with the SP2 version on an SP3 XP build. &amp;nbsp; This is as per a posted answer by Microsoft (Aug 2008) on a Microsoft TechNet forum at &lt;a rel="nofollow" target="_new" href="http://social.technet.microsoft.com/forums/en-US/winserverGP/thread/9301539b-9a3d-4701-8411-ca2b857167b2/"&gt;social.technet.microsoft.com/.../9301539b-9a3d-4701-8411-ca2b857167b2&lt;/a&gt; . &lt;/p&gt;
&lt;p&gt;Thanks for the suggestion about pinning redirected folders. Haven&amp;#39;t been able to find Vista equivilant to csccmd.exe yet but can see that csccmd has a /PIN switch.&lt;/p&gt;
&lt;p&gt;Cheers, will keep you posted.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=157" width="1" height="1"&gt;</description></item><item><title>re: User Data &amp; Settings: New DFS recommendations</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2008/06/06/user-data-amp-settings-new-dfs-recommendations.aspx#156</link><pubDate>Thu, 04 Dec 2008 01:16:42 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:156</guid><dc:creator>danholme</dc:creator><description>&lt;p&gt;Paul! &amp;nbsp; Thanks for the note!!! &amp;nbsp;I’m in the middle of a 10k user UD&amp;amp;S as well. &amp;nbsp;You’re right that MS’s tools (autocreation of Profile &amp;amp; folders) are not in any way least privilege—the client side code that does that was built long before “least privilege” was a real concern :-)&lt;/p&gt;
&lt;p&gt;I have some new information on permissions, but it depends on your folder namespace. &amp;nbsp;The %username% folder doesn’t need ANY permissions (to the user) thanks to the native traverse folders system privilege, unless your DFS namespace is built a certain way for the roaming profile, in which case the user needs READ (and only read) on the %username% folder.&lt;/p&gt;
&lt;p&gt;I discourage you from giving W on the %username% folder (above Documents/Desktop/etc.) because it gives the user the ability to add unmanaged files &amp;amp; folders to that root. &amp;nbsp;Instead, start giving permissions at the ‘specific folder’ (documents/desktop/etc.) level, and yes I believe we found that “M” (Modify) is enough, rather than Full Control.&lt;/p&gt;
&lt;p&gt;Thanks for all your other observations!!!! &amp;nbsp;I hope to have a chance to revise all my guidance next year as Win7 comes out (with backfill to XP &amp;amp; Vista).&lt;/p&gt;
&lt;p&gt;One other big note. &amp;nbsp;We’ve found it very helpful for many reasons to MANUALLY PIN all redirected folders offline on the computer (s) that a user uses on a day-to-day basis. &amp;nbsp;Helps availability, helps offline work (laptops), and provides a last-ditch backup/recovery solution. &amp;nbsp;You still want to turn off the default policy that automatically caches redirected folders, because you don’t want every user logging on to your conference room computer getting a full cache of their redirected folders. &amp;nbsp;It has to be done on a per-machine, per user bases. &amp;nbsp;CSCCMD.exe (in XP) and the equivalent command in Vista (which escapes me right now) can be automated to do this ‘manual’ step automatically.&lt;/p&gt;
&lt;p&gt;Please keep me posted… I *REALLY* appreciate feedback from the field. &amp;nbsp;UDS is such a beast, with so many moving parts, that all input helps!!!!!!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=156" width="1" height="1"&gt;</description></item><item><title>re: User Data &amp; Settings: New DFS recommendations</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2008/06/06/user-data-amp-settings-new-dfs-recommendations.aspx#155</link><pubDate>Thu, 04 Dec 2008 00:44:12 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:155</guid><dc:creator>paulbrod</dc:creator><description>&lt;p&gt;Dan,&lt;/p&gt;
&lt;p&gt;Thought I&amp;#39;d drop you a line concerning the our experience with permissions on %username% and subfolders, since you mention you&amp;#39;ll test MODIFY.&lt;/p&gt;
&lt;p&gt;We are implementing a similar UDS solution in a Windows 2003 R2 Native environment (10,000+ users), using XPSP3 (Desktops) and VistaSP1 (Laptops).&lt;/p&gt;
&lt;p&gt;We&amp;#39;ve decided to implement 26 DFS root namespaces such as \\domain\usersa through to \\domain\usersz. &amp;nbsp;And plan to use SAN replication not DFSR due to DFSR compatibility issues highlighted with our File archiving vendor, apparently this vendors file stubs don&amp;#39;t work too well with DFSR .&lt;/p&gt;
&lt;p&gt;Also amended the provisioning script to accept only users region, sAMAccount name, Firstname and Lastname as arguments. This provisions the user on the correct file server, assigns them their folder structure (with NTFS permissions detailed below) a user profile path, puts them in the correct policy group for folder redirection and can be used in any domain, Production or test.&lt;/p&gt;
&lt;p&gt;Redirected folders are Desktop, Documents (Pictures, Videos, Music follows) and we use Profile and Profile.v2.&lt;/p&gt;
&lt;p&gt;With respect to permissions:&lt;/p&gt;
&lt;p&gt;We too are using a Least User Privilge model and don&amp;#39;t use full control on any parent folder or subfolder for the user. &amp;nbsp;Instead we use something like modify but not delete parent, this I&amp;#39;ve found translates to an ACE of &amp;lt;Domain&amp;gt;\%username%:(OI)(CI)(RX,W,DC) on those redirected folders listed above. &amp;nbsp;We did originally use these permissions(X,RD,RA,REA,WD,AD,WA,WEA,DC,RC) because when viewed through the GUI, these items are cheked as they are when implemeted using (RX,W,DC) i.e. they appear to be exactly the same. However the later permission caused us no end of grief (access deinied, unable to create profile error messages), so we are now using the former permissions.&lt;/p&gt;
&lt;p&gt;Also found the DFSRoot permissions at the %username% level had to match the physcial namespace target or else the grief would return, also ref. KB907458.&lt;/p&gt;
&lt;p&gt;What&amp;#39;s interesting is that MS Best Practice suggests that the system should create the Profile directories or if you do have to precreate them, then use Full Control for the user on the Profile directories. Surely not a Least User Privilege approach?&lt;/p&gt;
&lt;p&gt;Thanks and keep up the great work.&lt;/p&gt;
&lt;p&gt;Paul&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=155" width="1" height="1"&gt;</description></item><item><title>re: Download the External Collaboration Toolkit for SharePoint</title><link>http://share.intelliem.com/cs/blogs/danholme/archive/2008/11/25/download-the-external-collaboration-toolkit-for-sharepoint.aspx#151</link><pubDate>Mon, 01 Dec 2008 18:46:28 GMT</pubDate><guid isPermaLink="false">a490a765-4c85-490a-a798-e10148c74a46:151</guid><dc:creator>tylerw</dc:creator><description>&lt;p&gt;thanks dan. That is what I thought. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://share.intelliem.com/cs/aggbug.aspx?PostID=151" width="1" height="1"&gt;</description></item></channel></rss>