Temporary user profile path left behind for bundles utilizing Dynamic Administrative User capability

  • 7016236
  • 26-Feb-2015
  • 26-Feb-2015

Environment

Novell ZENworks Configuration Management 11.3 Bundles
Novell ZENworks Patch Management 11.3

Situation

Managed devices are member of an Active Directory domain
Devices receive an Active Directory delivered group policy with the setting: Set roaming profile path for all users logging onto this computer

Applying a Patch Bundle or a Windows Bundles, having one or more actions configured to run as Dynamic Administrative User (DAU), can leave behind temporary user profile folders under C:\Users, where the folder name generally contains the workstation host name.

Resolution

Workaround:
Run a cleanup job which removes left over temporary user profiles.

Cause

With above group policy settings, Windows tries to enforce a roaming profile while the local DAU created user account does not have access to the network. Windows enforces the creation of a local temporary user profile. This temporary user profile path does not always get removed and can still contain data depending on the (patch) bundle actions which got carried out.

Please note that patches get deployed using the DAU user capability in ZPM 11.3.


Status

Reported to Engineering