Inside Windows 98

Previous chapterNext chapterContents


- 29 -

System Policies and User Profiles


Like Windows 95 before it, Windows 98 supports user profiles that enable multiple users to share a single workstation and still maintain individual settings and desktop properties. You also can use system policies to force settings and restrictions on users that prevent them from changing various desktop settings. You can even remove various desktop objects to help prevent access to local and network resources. Finally, system policies enable you to support roaming users. These users can log onto the network from any workstation but still retain their own desktop configurations that follow them to each logon workstation.

This chapter explains how to implement system policies and user profiles in Windows 98, covering the following topics:

Before delving into system policies and the tools you use to create and manage them, you need a basic understanding of system policies and user profiles.

Understanding Profiles and Policies

Windows 98 uses two mechanisms to control a user's desktop and working environment, as well as the resources that the user can access both locally and on the network. These two mechanisms are explained in the following sections.

Understanding User Profiles

User profiles define the working environment and desktop for a particular user. These include installed applications, desktop shortcuts, wallpaper, and other desktop properties and resources. In Windows 98, these settings are stored in USER.DAT, one of two files that make up a user's Registry. The other file, SYSTEM.DAT, contains system-related settings that do not change from user to user.

User profiles also comprise a set of folders that contain the user's desktop environment. By default, these folders are located in the Windows folder and include the Desktop, Start Menu, Cookies, Application Data, History, NetHood, and Recent folders. These folders collectively store your desktop and working resources (desktop shortcuts, for example). The USER.DAT portion of the Registry and these folders work in concert to provide the interface you see when you work under Windows 98.

You can configure a Windows 98 to support separate user profiles, enabling a single workstation to support multiple users, each with a unique desktop environment. When Windows 98 is configured to support these unique user profiles, each user has a unique USER.DAT file and a set of custom folders to contain his or her working environment. These folders are created under \Windows\Profiles\username, where username is the name under which the user logs on to Windows 98. If your Windows 98 logon name is joeb, for example, your profile folders would be located in \Windows\Profiles\Joeb. This folder would contain the Desktop, Start Menu, and other folders mentioned previously.

When you log on to a Windows 98 workstation, Windows 98 determines whether you have ever logged on to the system before. If you have not, and multiple user profiles have not been enabled, Windows 98 simply creates a password cache file using your user name and the extension PWL to name the file and places the file in the Windows directory. If multiple profiles are enabled, Windows 98 performs the additional step of creating the directory structure under the \Windows\Profiles folder to contain your custom desktop settings. The next time you log on to that workstation, Windows 98 will use your USER.DAT file and profile folders to define your desktop and working environment.

The process described above applies to log on to a specific workstation. You also can have your user profile follow you wherever you roam on the network. These are called roaming profiles. Configuring and using roaming profiles is explained later in this chapter in the section "Supporting Roaming Users."

Understanding System Policies

System policies, which are stored in a special policy file (typically, CONFIG.POL), enable Windows 98 to override various settings in the user's Registry, both for the user and for the system. Policies also enable a system administrator to restrict access to specific Windows 98 interface objects and network resources.

You can, for example, prevent users from changing display settings or configuring other hardware settings. You can remove such elements as the Network Neighborhood folder from the desktop. You can remove the Entire Network object from the Network Neighborhood folder to prevent browsing to network resources outside of the workgroup or domain. Several (or all) accounts can use the same policy file, or you can associate specific groups with specific policy files or even use a separate policy file for each user.

You create system policy files using the System Policy Editor, which is explained in detail later in this chapter in the section "Using the System Policy Editor." For now, just understand that you can use the System Policy Editor as an interface to define a collection of settings that are stored in a special policy file that is applied to one or more users to control their Windows 98 environment.

A policy file can contain several different groups of settings. When you create a new policy file, the System Policy Editor creates Default User and Default Computer settings by default (see Figure 29.1). The properties associated with these two objects apply to all users who do not have their own unique set of properties stored in the policy file. Figure 29.2 shows an example of the type of restrictions you can apply within a policy file.

FIGURE 29.1 By default system policies include settings for all users and computers not otherwise specified in the policy file.

FIGURE 29.2 You can apply restrictions to specific users or groups of users through the policy file.


NOTE: User settings in a policy file correspond to the settings in USER.DAT. Computer settings in a policy file correspond to SYSTEM.DAT. A system policy file therefore controls both system- and user-specific settings.

At this point the key to understanding policy files is that although you create a single file, that single policy file can contain unique settings for individual users, groups of users, or all users. You might, for example, create a policy file in which you modify the Default User and Default Computer objects to contain the settings desired for all users, then add individual user and computer objects for any user or computer for which there should be exceptions to those defaults.

In addition to a system policy file, you also need the appropriate network client for your network environment in order to implement system policies. For NT networks, use the Client for Microsoft Networks. Use the Client for NetWare Networks for NetWare networks.

Understanding Mandatory Profiles

In place of system policies you can use mandatory profiles. A mandatory profile is really nothing more than the USER.DAT portion of the Registry that has been renamed USER.MAN. You place the USER.MAN file in the user's home directory on the logon server. When the user logs on, Windows 98 downloads the USER.MAN file, using it in place of the USER.DAT file residing on the client's computer. Therefore, USER.MAN (the mandatory profile) functions as the user portion of the Registry.

Mandatory profiles are different than system policies in that mandatory profiles control all user settings. System policies enable you to control a subset (or all) of the users' settings, with the users having control of the remaining settings. Mandatory profiles also differ from system policies in that mandatory profiles control only user-level settings and not system-level settings.

You can use mandatory profiles or system policies, but not both. If a mandatory profile is in place for a user and Windows 98 also detects a system policy file at logon, the system policy file takes precedence over the mandatory profile.

To create a mandatory profile, you log on to a Windows 98 workstation and create the desired desktop environment. In addition to manually manipulating the desktop, you can use the System Policy Editor to modify the workstation's registry to apply any desired restrictions.

When you save the Registry from the System Policy Editor, the Registry is saved as two files, USER.DAT and SYSTEM.DAT. You then use the resulting USER.DAT file as the mandatory profile. To do so, you copy USER.DAT to USER.MAN, placing the USER.MAN file in the user's home logon folder. In the case of Windows NT, this is the home folder specified in the user's account. In the case of NetWare, the user's mail folder is used to store the mandatory profile.

Enabling User Profiles

The first step in using either system policies or mandatory profiles is to configure the workstation for user profiles. You can perform this operation manually from each workstation, or if you are going to be using system policies, you can force the change to user profiles through those system policies. The following sections explain both approaches.

Manual Setup of User Profiles

You can configure a Windows 98 workstation to employ user profiles through the Passwords object in Control Panel. Open the Control Panel and double-click on the Passwords icon and click on the User Profiles tab to display the User Profiles page shown in Figure 29.3.

FIGURE 29.3 Enable user profiles through the Passwords object in the Control Panel.

The following list summarizes the controls on the User Profiles page:

Configuring Automatically for User Profiles

Rather than configuring each workstation individually for user profiles, you might prefer to have them configured automatically when your users log on to the network. You can accomplish this through system policies.

Refer to the section "Creating and Using System Policies" later in this chapter to learn how to create a system policy file. In the System Policy Editor, double-click on the Default Computer icon to display the Default Computer Properties sheet. Expand the Windows 98 System branch and then expand the User Profiles branch. The property sheet should be similar to the one shown in Figure 29.4.

Place a check in the Enable User Profiles check box. Save the system policy file in the appropriate folder (NETLOGON for NT or sys\public for NetWare). Configure user accounts to use the system policy file, as explained later in the section "Creating and Using System Policies."

FIGURE 29.4 The User Profiles branch enables you to force the implementation of user profiles at logon.

Using the System Policy Editor

The System Policy Editor is the tool you use to create and modify system policy files. You also can use the System Policy Editor to modify a workstation's registry. The System Policy Editor is a Windows 98 application and must be run on either a Windows 98 or Windows 95 workstation. You must use a Windows NT version of the System Policy Editor on a Windows NT computer when creating policies for NT users.

Installing System Policy Editor

The System Policy Editor files are located on the Windows 98 CD-ROM in the \Tools\Apptools\Poledit folder. To install the software, log onto the Windows 98 computer from which you want to run the Policy Editor. Open the Control Panel and double-click the Add/Remove Programs icon and then click on the Windows Setup tab. After Windows 98 completes its search for installed components, click the Have Disk button. Browse and select the \Tools\Apptools\Poledit folder on the CD-ROM and choose OK. Choose OK in the Install from Disk dialog box to display the Have Disk property page shown in Figure 29.5.

FIGURE 29.5 Select which components to install for Policy Editor.

Choose the System Policy Editor check box to have Windows 98 install the System Policy Editor and associated files. If you intend to assign policies by groups, also enable the Group Policies check box. This causes Windows 98 to install the files necessary to support group policies (explained in the section "Using System Policies"). Choose Install to complete the software installation.

Running System Policy Editor

To start System Policy Editor, choose Start | Programs | Accessories | System Tools | System Policy Editor, or execute the file POLEDIT.EXE in the Windows folder. The System Policy Editor will start and display a blank work area. You then can start a new policy file, open an existing policy file, or open a registry, either on the local computer or on a remote computer.


NOTE: Remote computers must be configured to allow remote administration to enable you to open their registries across the network. They also must be running the Remote Registry Service and be configured for user-level access.

Choose one of the following commands from the File menu, as appropriate to your situation:

Understanding Policy Editor Template Files

The System Policy Editor uses a template file to control the settings that you can modify through the System Policy Editor's interface. The default template file, which Windows 98 places in the \Windows\Inf folder, is named WIN98.ADM. You can modify the contents of WIN98.ADM to add other features and their corresponding registry settings to the policy file. You also can add other template files to the System Policy Editor so that it reads these template files at startup and incorporates their contents into the System Policy Editor interface.

In addition to the default WIN98.ADM template, the Windows 98 includes a template file name PWS.ADM that enables you to specify policy settings that control Personal Web Server. PWS enables a Windows 98 computer to act as a Web server for its local content. Adding the PWS.ADM template to the System Policy Editor enables you to control each user's Web server (if installed).

System Policy Editor makes it easy to add new template files. Follow these steps to add or remove template files:

1. Start the System Policy Editor and make sure that no policy file is open.

2. Choose Options, Policy Template to display the Policy Template Options dialog box shown in Figure 29.6.

3. If adding a template, click Add, and browse for and select the template file you want to add.

4. If removing a template, select the template from the list and click Remove.

5. Choose OK to close the dialog box.

FIGURE 29.6 Use the Policy Template Options dialog box to add and remove template files.

You also can manually add policy templates to your System Policy Editor configuration. Follow these steps:

1. Close System Policy Editor if it is running.

2. Verify that the desired ADM file exists in the \Windows\Inf folder; if not, copy it there.

3. Open the Registry Editor, and then open the key HKEY_CURRENT_USER\ Software\Microsoft\Windows\CurrentVersion\Applets\Poledit.

4. Right-click on PolEdit in the tree pane and choose New, String Value. Registry Editor creates a new string value in the Contents pane.

5. Rename the new Registry setting created in step 4 to TemplateN, where N is the next available template number. If you have only one other template (Template0), for example, name the new setting Template1.

6. Double-click on the new template setting to open the Edit String dialog box to specify its value. Specify the path to the new template file, such as c:\windows\inf\pws.adm, and choose OK.

7. Close the Registry Editor.

8. Start System Policy Editor.


TIP: If you have user profiles enabled on your computer, the Registry Editor will add identical settings for the new template files to the Registry key for the username under which you are currently logged on. If you are logged on with the username jane, for example, new values for the templates will be created in HKEY_USERS\jane\Software\Microsoft\Windows\ CurrentVersion\Applets\PolEdit.

Creating and Using System Policies

Creating a system policy file comprises several steps, some of which are optional depending on whether you want to assign policies to specific users or groups. These steps are summarized in the following list:

The following sections explain each of these steps.

Specifying Default User Settings

In a policy file you can have several objects that contain groups of settings. The Default User object contains the policy settings that are applied to all users who do not have their own user object in the policy file.

The Default User object contains settings that control the following user-related areas:

The settings within each of these groups really requires no explanation because the purpose of the settings is made plain in the System Policy Editor. At this point, simply understand that you use the settings in the Default User object to control the user settings (as defined previously) for any user who does not have his or her own user object in the policy file. Specify the settings in the Default User object accordingly, as desired.

Specifying Default Computer Settings

The Default Computer object in the policy file enables you to set hardware- and system-related settings that will apply to all computers that do not have their own computer object specified by name in the policy file. The settings you can control with the Default Computer object include the following:

As with the user-related settings described in the previous section, the computer settings are generally self explanatory to an administrator (and most to the average user, as well). The key point to understand is that the settings in the Default Computer object apply to all computers that do not have their own, specific object in the policy file. Specify the settings in the Default Computer object accordingly, as desired.

Adding Individual Users

You can apply policy settings to individual users, as well as assign them by default through the Default Users object. To do so, open the policy file and choose Edit, Add User. System Policy Editor prompts you for the name of the user to add. Specify the user's account name and click OK. System Policy Editor creates an object in the policy file for that user (see Figure 29.7).

FIGURE 29.7 System Policy Editor creates a separate object to contain the user's settings.

The settings you can specify for individual users are the same as for the Default User object. Specify the settings that you want applied to the specified user.

Adding Individual Computers

As with individual users, you can add objects to the policy file to accommodate settings for specific computers. These settings are used when any user logs on from that particular computer. This enables you to control settings by computer, as well as by user.

To create a computer object in a policy file, choose Edit, Add Computer. System Policy Editor prompts you for the name of the computer. Enter the name and click OK. A Property object for the computer is added to the policy file. Simply double-click on the object to set its properties, just as you would for the Default Computer object. The settings available in each are identical.

Adding Groups

In addition to assigning properties and restrictions through individual user objects and the Default User object, you can create group objects that assign properties and restrictions based on the users' group membership. Using group policies requires installing group policy support on the user's workstation. To install group policy support, follow these steps:

1. On each workstation, open the Control Panel and double-click the Add/Remove Programs icon.
2. Click on the Windows Setup tab and wait for Windows 98 to scan the system for installed programs.

3. Scroll through the list and double-click System Tools.

4. In the list of tools, locate and place a check mark beside the Group Policies item.

5. Choose OK; then OK again to install the necessary files.

This installation process installs the GROUPPOL.DLL to the \Windows\System folder and modifies the computer's Registry to enable group policy support. If you experience problems installing group policy support using the previous steps, run through the process again, but at step 3, click Have Disk instead. Browse to the \Tools\Apptools\Poledit folder and choose OK, then OK a second time. Click the Install button to complete the installation.

A single user can be a member of several groups, each of which might have different policy settings. Group policies are downloaded from the server starting with the group that has the lowest priority and moving to the group with the highest priority. In this way, the policy settings for the highest priority group overrides previously loaded policies. If an individual user object exists in the policy file for the user, those settings are used instead of the settings in any group policies.

Saving the Policy File

For Windows 98 clients, the policy file is stored not on the local workstation but instead on the logon server. In the case of a Windows NT server, the policy file is stored in the NETLOGON share on the primary domain controller (\\primary domain controller\netlogon), which by default is located in \Winnt\System32\Repl\Import\Scripts on the PDC server. In NetWare environments, the CONFIG.POL file is stored in \\preferred server\sys\public. After you have configured the policy file as desired, save it to whichever of these directories is appropriate, using the file name CONFIG.POL.

Configuring User Accounts for System Policies

When a user logs off, Windows 98 automatically places a copy of the user's USER.DAT file, with all policies applied, to the user's home directory. The first step in configuring user accounts for system policies is to specify in the user's account his home directory. In Windows NT, you do so from the User Environment Profile dialog box (see Figure 29.8), which you access through User Manager for Domains. Under NetWare, you use the SysCon utility.

FIGURE 29.8 Specify the home directory in the User Environment Profile dialog box.


TIP: Although the User Environment Profile dialog box provides a control for specifying that a drive letter on the client computer be mapped to a remote share, this setting works only for Windows NT clients. Although it does set the user's home folder property, it does not cause the specified drive letter to be mapped to the folder. You must perform the desired drive mapping through the user's logon script with the appropriate NET USE command in addition to specifying the home directory in the User Environment Profile dialog box.

By default, Windows 98 supports automatic downloading of the system policy file at logon. The method described previously enables automatic downloading. When a large number of users log on at once, you might experience slow performance if only one policy file is used. To help overcome this potential problem, Windows 98 supports load balancing, which causes the workstation to pull the policy file from the current logon server rather than specifically from the PDC. Follow these steps to take advantage of load balancing:

1. Place the policy file in the NETLOGON share of the PDC.

2. Replicate the policy file to all other logon servers (BDCs).

3. Open the system policy file in System Policy Editor and then open the Default Computer object.

4. Open Windows 98 Network and expand the Update branch.

5. Place a check in the Remote Update box, set Update mode to Automatic, and place a check in the Load Balance check box.

6. Save the policy file.

7. Replicate the policy file to the BDCs.

In some cases it is necessary to implement manual downloading of the policy file. You might want to specify a different policy file location for some users, or some workstations might be using real-mode network clients, such as NETX or VLM. In these case you need to configure the computers for manual downloading. To do so, enable the Remote Update policy for the Default Computer object as explained in the previous steps, but choose Manual for the update mode and specify the UNC path to the policy file.


NOTE: Systems using a real-mode network client require that the policy file be placed on a mapped drive rather than a UNC path.

Supporting Roaming Users

A roaming profile is one that follows the user wherever he logs on to the network. With a roaming profile, all desktop and working environment properties follow the user to each computer he uses on the network.


NOTE: Roaming profiles enable a user to move from one Windows 98 or Windows 95 workstation to another, but do not follow the user to Windows NT workstations because the two profiles are not compatible with one another.

Enabling roaming profiles is a simple task, and this chapter has already covered how to accomplish these steps. To enable roaming profiles for a user, follow these steps:

1. Configure the workstations on which the user will log on to use user profiles.

2. Specify a home directory on the server within the user's logon account on the Windows NT or NetWare server.

3. Configure the user's working environment either by saving a copy of the appropriate USER.DAT file to the user's home directory through a system policy object, or by simply configuring the current workstation according to the user's preferences (then log off).

4. Log on to the network to test the user's profile. When you log off, Windows 98 automatically stores the USER.DAT file in the home directory.


Previous chapterNext chapterContents

© Copyright, Macmillan Computer Publishing. All rights reserved.