Ok, so I think I've managed to do the roaming profiles bit.
I created a folder called "Default User" in the root of NETLOGON share. In there I put the NTUSER.dat file and some other bits copied from a local profile.
I followed some instructions on this page to set the permissions and created a group policy to allow the administrator access - I noticed this only works on new profile folders.
Security Recommendations for Roaming User Profiles Shared Folders: Group Policy
I also fumbled around and managed to force ownership of the locked folders to the administrators so I could remove them and then logged in on the client PC to create them again but this time with the group policy set so the administrator could access them them.
I'll have another go at the documents shares next...


LinkBack URL
About LinkBacks
Reply With Quote