7.0

Table Of Contents
Table 182. Minimum NTFS Permissions Required for the User Profile Repository and Redirected Folder
Share
User Account Minimum Permissions Required
Creator Owner Full Control, Subfolders and Files Only
Administrator None. Instead, enable the Windows group policy setting, Add the Administrators
security group to the roaming user profiles. In the Group Policy Object Editor, this
policy setting is located in Computer Configuration\Administrative
Templates\System\User Profiles\.
Security group of users
needing to put data on share
List Folder/Read Data, Create Folders/Append Data, Read Attributes - This Folder
Only
Everyone No permissions
Local System Full Control, This Folder, Subfolders and Files
Table 183. Share Level (SMB) Permissions Required for User Profile Repository and Redirected Folder
Share
User Account Default Permissions Minimum Permissions Required
Everyone Read only No permissions
Security group of users needing to put data
on share
N/A Full Control
For information about roaming user profiles security, see the Microsoft TechNet topic, Security
Recommendations for Roaming User Profiles Shared Folders.
http://technet.microsoft.com/en-us/library/cc757013(WS.10).aspx
Creating a Network Share for View Persona Management
You must follow certain guidelines when you create a shared folder to use as a profile repository.
n
If you use Windows 8 desktops and your network share uses a OneFS file system on an EMC Isilon
NAS device, the OneFS file system must be version 6.5.5.11 or later.
n
You can create the shared folder on a server, a network-attached storage (NAS) device, or a network
server.
n
The shared folder does not have to be in the same domain as View Connection Server.
n
The shared folder must be in the same Active Directory forest as the users who store profiles in the
shared folder.
n
You must use a shared drive that is large enough to store the user profile information for your users. To
support a large View deployment, you can configure separate repositories for different desktop pools.
If users are entitled to more than one pool, the pools that share users must be configured with the same
profile repository. If you entitle a user to two pools with two different profile repositories, the user
cannot access the same version of the profile from desktops in each pool.
n
You must create the full profile path under which the user profile folders will be created. If part of the
path does not exist, Windows creates the missing folders when the first user logs in and assigns the
user's security restrictions to those folders. Windows assigns the same security restrictions to every
folder it creates under that path.
For example, for user1 you might configure the View Persona Management
path \\server\VPRepository\profiles\user1. If you create the network share \\server\VPRepository,
and the profiles folder does not exist, Windows creates the path \profiles\user1 when user1 logs in.
Windows restricts access to the \profiles\user1 folders to the user1 account. If another user logs in
with a profile path in \\server\VPRepository\profiles, the second user cannot access the repository
and the user's profile fails to be replicated.
Setting Up Desktop and Application Pools in View
308 VMware, Inc.