Troubleshoot without logging
If no logging at all is taking place, try the troubleshooting approach used in the following example. It is designed to help you work out which configuration settings are being read, establish where they are being read from (when multiple ADM files are present), and check that the log file correctly tracks changes made to profiles. The strategy creates a small test OU to which a test user logs on, allowing you to create profile modifications that you then track in the log file and Resultant Set of Policies (RSoP) report.
The deployment in this example has Citrix virtual apps servers running on Windows Server 2003 with users connecting to their published resources using the Plug-in for Hosted Apps for Windows. The deployment uses OU-based GPOs. INI file-based configuration is not used.
Caution: Editing the registry incorrectly can cause serious problems that might require you to reinstall your operating system. Citrix cannot guarantee that problems resulting from the incorrect use of Registry Editor can be solved. Use Registry Editor at your own risk. Be sure to back up the registry before you edit it.
- Remove from the production environment one of the Citrix virtual apps servers that hosts the Citrix user profiles. And add it to a new OU containing just this server.
- Remove and reinstall Profile Management on the server. When reinstalling, check that short file names (also known as 8.3 file names) are activated. As this example uses Windows Server 2003, you do this as follows:
- If the following registry entry is set to 1 (DWORD value), set it to 0 and reinstall Profile Management: HKLM\System\CurrentControlSet\Control\FileSystem\NtfsDisable8Dot3NameCreation. This enables support for short file names.
- If the entry is not set to 1, reinstall Profile Management to a location where each subfolder name is eight characters or less, for example c:\prof-man. For later operating systems, you do not need to adjust this registry entry.
- Log on as a domain administrator to the server.
- Examine the local policy and remove the ADM file at this level.
- Delete any links to GPOs assigned to your new OU.
- On the server, delete the key and all subkeys from Registry Editor:
- Remove any Profile Management .ini file.
- Using My Computer > Properties > Advanced, delete all profiles except those profiles that you want to test. Research any errors that appear.
- So that you can check the Profile Management log file when logging on as a user, give the Authenticated Users group full control of the file. This is C:\Windows\System32\LogFiles\UserProfileManager\<domainname>#<computername>_pm.log (where <domainname> is the computer’s domain and<computername> is its name). If the domain cannot be determined, the log file is UserProfileManager.log.
- Create a GPO that contains only the following settings, and link it to your new OU. Ensure that the GPO is assigned to the Authenticated Users group. Enable these settings:
- Enable Profile Management.
- Path to user store.
- Enable logging.
- Log settings. Scroll to select all settings in this section of the ADM file.
- Migration of existing profiles. Select Roaming and local profiles.
- Local profile conflict handling. Select Rename local profile.
- Delete locally cached profiles on logoff. Disable the setting Process logons of local administrators. It helps when troubleshooting because, if Profile Management is misconfigured and prevents user logons, you are still able to log on as an administrator.
- Control how the GPO link is applied to the OU by right-clicking the OU and selecting Block Inheritance.
- Create a domain test user who has never logged on and who is not a member of any group that is a local administrator on the server.
- Publish a full desktop to this user and make sure the user is in the Remote Desktop Users group.
- If the domain has multiple domain controllers (DCs), force AD replication between all the DCs in the same site as the server.
- Log on to the server as domain Administrator, delete the log file, restart the Citrix Profile Management service, and run
- Check the registry and make sure the only values in
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Citrix\UserProfileManager\are the ones for your new GPO.
- Log out as Administrator.
- Using the Plug-in for Hosted Apps, log on to the published full desktop as the new domain test user.
- Make some setting changes to Internet Explorer, and create a blank test file in your My Docs folder.
- Create a shortcut to the Profile Management log file. Open it and examine the entries. Research any items that require attention.
- Log out and then back in as domain Administrator.
- Generate an RSoP report for the test user and the server.
If the report does not contain what you expect, research any items that require attention.