Tuesday, March 04, 2008

The_Simpsons-Jeff_AlbertsonI've worked with and around networks at many levels for years.  What I haven't done, however, is work as a network administrator.  I've found that most good net admins both look and behave like Jeff Albertson (a.k.a. The Comic-Book Guy).  They just seem to have that special something.

Regardless, you may still find yourself with the need to perform some basic administration on an Active Directory.  For example, you may need to share a network drive at the logon.  Well, here's how you do just that:

Note: I'm not a net admin.  I only play one when absolutely necessary.  The method below is based on what worked for my environment.  Your mileage may vary.

How to share a user drive at logon

Create the folder & set properties

  1. Create the user folder on a server named the same as the user to share it with a dollar sign ($) at the end, e.g. MattB$
  2. Right-click, Sharing and Security...
  3. Change to Share this folder, then click Permissions
  4. Delete the "Everyone" account, and add the user who will own this directory
  5. Change their rights to allow Full Control for this user
  6. Click OK to get to properties, then click on General tab
  7. OK

Create the logon script

  1. Start notepad.exe and add the following line:
    net use u: \\servername\%username%$
  2. Change "servername" to the name of your server, and change the "u" to whatever drive label you want to use; X: or Y: or Z:, etc
  3. Save the file as logon.bat to your desktop
  4. Right-click the file and choose "copy"

Edit your group policy

  1. Get to the group policy you wish to edit by opening AD Users & Computers, right click the domain, click properties, Group Policy tab, select the GP and click Edit
  2. Navigate to User Configuration/Windows Settings/Scripts
  3. Double-click Logon, click "Show Files..." then right click and paste the logon.bat file there
  4. OK all the way out, and close AD editors

Either wait for your AD to replicate these rules out or go to a command prompt on your AD server and type
gpupdate /force

At logon your user will be auto-shared this device

Other reading: