Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


February 2008

Best Practices for Managing User Data and Settings, Part 1

An effective server-side back end will help you handle an otherwise intricate chore
RSS
Subscribe to Windows IT Pro | See More User Management and Profiles Articles Here | Reprints
Or get the Monthly Online Pass—only $5.95 a month!

In recent months, I’ve worked with several clients on projects designed to improve the management of user data and settings (UDS). Insufficiently or incorrectly managed UDS can have a significant negative effect on your IT department’s service delivery. By putting the right pieces in place, you can reduce costs, increase security, enable mobility, improve productivity, and ensure business continuity.

Windows provides most of the pieces: redirected folders, roaming profiles, quotas, file screens, DFS namespaces, encryption, and offline files. All you need to do is add the right people, processes, and supporting scripts and tools. By putting all these pieces together in just the right way, you can create a framework for effectively managing UDS. But it’s not easy—there are many moving parts. And although there’s a slew of documentation about profiles and redirected folders, very little of it deals with the crazy interactions between all these technologies and the various types of data that you need to manage in your enterprise.

In this two-part series, I’ll offer some design guidance to help you create a UDS management framework. I’ll also help you unify UDS management for both Windows Vista and Windows XP users. For some good foundational reading before diving into these best practices, I recommend that you read chapter 3 of the Windows Administration Resource Kit. The chapter goes into far more detail than I have space for here. The resource kit also contains great tools and scripts to help you implement a UDS management framework. (Although the book is part of the Windows Server 2008 Resource Kit, the content also applies to Windows Server 2003 and to Vista and XP clients.)

In this first part of the series, let’s dive into some best practices for the server side of the equation. I’ll look at the physical namespace (i.e., folders and permissions), the SMB namespace (i.e., shares), and the DFS namespace that will give you the most effective back end for UDS management. In Part 2, I’ll look at the client-side components.

Identify Your Business Requirements
First, let’s get some definitions out of the way. User data refers to files created by and necessary for an individual user—items in a user’s Documents folder (My Documents in XP) or on their desktop. Settings refers to everything from a user’s Microsoft Outlook configuration, custom dictionary, quick launch shortcuts, templates, and desktop wallpaper to his or her Microsoft Internet Explorer (IE) Favorites. Windows has a number of data and settings stores for UDS, including My Documents, Desktop, Favorites, AppData, and the ntuser.dat registry file. These data stores can reside physically on the local system, on a network server, or both. For laptop users, in fact, data stores are in both local and network locations, with technologies including offline files and roaming profiles keeping the two locations in sync.

Before you begin designing a UDS management framework, spend some time identifying the business requirements that drive such a project. I suggest that they’ll fall into the following categories:

  • Security—You must ensure that the data your users create is secure.
  • Mobility—Users should have access to their data and settings not only from their desktop PC or personal laptop but also from conference rooms and other computers.
  • Availability—When a user gets a new or replacement system, his or her data and settings should be fully available at first logon.
  • Resiliency—If a user’s hard disk fails or is stolen, his or her business data and settings shouldn’t be permanently lost.

Preview the Best Practice Design for a UDS Framework
After identifying your strategic requirements, you can begin to design a framework that tackles UDS according to those requirements. Here’s a quick overview of what your UDS framework will comprise.

Redirected folders. Redirected folders ensure that critical stores of user data are located on file servers. Users on Windows clients will continue to access their data in their Documents folder, on their desktop, in their Favorites folder, and in media folders such as Music, Pictures, and Videos. The functionality of redirected folders makes it transparent to users that the physical data stores for those folders are on the network.

Offline files. Laptop users will leverage offline files so that their data is available when they’re disconnected from the network. The offline files cache will be secured with encryption to reduce the risk of data leakage when a laptop is lost or stolen.

Roaming profiles. You’ll use roaming profiles to meet the mobility, availability, and resiliency requirements for users’ registry hives—the ntuser.dat file in the root of their profiles. You’ll also include the App- Data folder in the roaming profile. For reasons I’ll detail in Part 2, although it’s technically possible to redirect AppData, in most scenarios it’s likely that redirection will be a future-state, and until then AppData will be managed as part of the roaming profile. Chances are the registry file and AppData folder are the only two items you’ll use roaming profiles to manage. Users’ profiles will be very small indeed, and for that reason, roaming profiles will effectively support those two settings stores.

DFS namespaces. DFS namespaces will abstract the physical location of user data stores so that users’ data can be managed easily and moved with minimal impact.

Unmanaged data. Classes of data that shouldn’t be stored on network servers (e.g., users’ personal music collections) will be excluded from both redirected folders and roaming profiles so that they remain on the users’ local hard disk.

Quotas and file screens. You can optionally implement quotas and file screens on server data stores to manage the quantity and types of data stored there.

   Previous  [1]  2  3  Next 


Reader Comments
Fine

farasathassan January 31, 2008 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

How can I uninstall the Microsoft Java Virtual Machine (JVM) from Windows XP?

...

Managing Virtual Sprawl

As some wise person once said, nothing is ever truly free. Such is the case with VMs, which can quickly mutate from a cost-reducing Dr. Jekyll into a time-consuming, profligate nightmare that would do Mr. Hyde proud. ...


Windows OSs Whitepapers Replay for Exchange: Enterprise Protection and an Affordable Price

Are You Satisfied?

A Preliminary Look at Deployment Plans for Microsoft Windows Vista

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Disaster Recovery and Backup

A Guide to Windows Certification and Public Keys

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Critical Challenges of ESI & Email Retention
Are you storing too much electronic information? Get expert legal advice and better understanding of what you are required to do as an IT professional.

Become a fan of Windows IT Pro on Facebook!
Join us on Facebook and be a fan of Windows IT Pro!

Sustainable Compliance: Are You Having a Resource Crisis?
Read this white paper to examine trends in compliance and security management and review approaches to reducing the cost and operational burden of compliance.

Rev Up Your IT Know-How with Our Recharged Magazine!
The improved Windows IT Pro provides trusted IT content with an enhanced new look and functionality! Get comprehensive coverage of industry topics, expert advice, and real-world solutions—PLUS access to over 10,000 articles online. Order today!

Get It All with Windows IT Pro VIP
Stock your IT toolbox with every solution ever printed in Windows IT Pro and SQL Server Magazine plus bonus Web-exclusive content on hot topics. Subscribe to receive the VIP CD and a subscription to your choice of Windows IT Pro or SQL Server Magazine!



Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.
Windows IT Pro Home Register About Us Affiliates / Licensing Media Kit Contact Us/Customer Service  
SQL Connected Home IT Library SuperSite FAQ Wininfo News
Europe Edition Office & SharePoint Pro Windows Dev Pro Windows Excavator 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing