From 181632fd9385cd90bec7386ad6003108f39517d8 Mon Sep 17 00:00:00 2001 From: John Terpstra Date: Wed, 15 Jan 2003 21:42:18 +0000 Subject: dded further comment. (This used to be commit 094726d84d08a83dcce8e1b96c3b3623ef9f7382) --- docs/textdocs/CreatingGroupProfiles-Win2K.txt | 12 ++++++++++++ 1 file changed, 12 insertions(+) (limited to 'docs') diff --git a/docs/textdocs/CreatingGroupProfiles-Win2K.txt b/docs/textdocs/CreatingGroupProfiles-Win2K.txt index 61d12aa724..31af9c2305 100644 --- a/docs/textdocs/CreatingGroupProfiles-Win2K.txt +++ b/docs/textdocs/CreatingGroupProfiles-Win2K.txt @@ -30,3 +30,15 @@ nominated. Done. You now have a profile that can be editted using the samba-3.0.0 profiles tool. + + +> Keep profiles clean and small by making them mandatory. +> See the Win2K/WinXP resource kits for details how to create a mandatory profile. +> +> Can you do this when using Samba as a PDC? I thought you could only do +> policies if you had a Win2K server? + +No difference. Samba handles the profile ACLs the same way Win2K does. +But understand that it is the Win2K client that does all the processing +of the SIDs on the ACLs in the profile NTUser.DAT file. + -- cgit