• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / System Administration / Creating a mandatory profile in Windows 7

Creating a mandatory profile in Windows 7

2012-07-19 by Jason

It’s been a little while since I had to create a mandatory profile. I have done it on Windows XP computers at previous organizations and clients but with a new organization actually using Windows 7, the situation has finally come about for a lab/kiosk environment that could make use of a mandatory profile. To refresh myself, I gathered a few resources on the topic.

Microsoft’s TechNet Library has an entry called “Creating a Mandatory User Profile”. It sounds like it should be a one-stop shop for the information needed. Unfortunately, it redirects you to other steps and the whole process feels unrefined.

Before you can create a mandatory profile, you have to follow another Microsoft TechNet entry Configuring Standard User Accounts. Specifically, a subsection of the article covers “To create a default user profile”. Be sure you are doing this process on a new Windows 7 test machine, not something you expect to use in production. The process involves running the command:

c:Windowssystem32sysprepsysprep.exe /oobe /reboot /generalize /unattend: c:unattend.xml

Before you can run the command, you have to create the unattend.xml file and place it at C: (or update the command accordingly). To create the unattend.xml file with the CopyProfile attribute set to true, Microsoft points users to the Windows Automated Installation Kit. Instead of that route, it’s easier to copy the appropriate (32-bit or 64-bit) files from this TechNet blog and create an unattend.xml file at the root of C drive.

x86

<?xml version=”1.0″ encoding=”utf-8″?>
<unattend xmlns=”urn:schemas-microsoft-com:unattend”>
<settings pass=”specialize”>
<component name=”Microsoft-Windows-Shell-Setup” processorArchitecture=”x86″ publicKeyToken=”31bf3856ad364e35″ language=”neutral” versionScope=”nonSxS” xmlns:wcm=”http://schemas.microsoft.com/WMIConfig/2002/State” xmlns:xsi=”http://www.w3.org/2001/XMLSchema-instance”>
<CopyProfile>true</CopyProfile>
</component>
</settings>
</unattend>

x64
<?xml version=”1.0″ encoding=”utf-8″?>
<unattend xmlns=”urn:schemas-microsoft-com:unattend”>
<settings pass=”specialize”>
<component name=”Microsoft-Windows-Shell-Setup” processorArchitecture=”amd64″ publicKeyToken=”31bf3856ad364e35″ language=”neutral” versionScope=”nonSxS” xmlns:wcm=”http://schemas.microsoft.com/WMIConfig/2002/State” xmlns:xsi=”http://www.w3.org/2001/XMLSchema-instance”>
<CopyProfile>true</CopyProfile>
</component>
</settings>
</unattend>

Now you can run the sysprep command. It will restart the computer and copy over the profile you are logged into to the default profile. As I did not have much customization to do, instead trying to use Group Policy to control the experience, this was sufficient for me. If you need to customize the profile more before gathering it, this blog presents a further approach with putting the computer in audit mode by hitting Ctrl+Shift+F3.

With sysprep re-activating the out-of-box experience, you will have to setup a user with a password. They will be an administrator by default and you will be automatically logged into the machine and disconnected from a domain if you were previously connected.

Once logged in, you can copy the profile to a local or server location. The Microsoft TechNet article says to type ‘user profile’ at Start and then open “Configure advanced user profile properties”. This didn’t work for me as it only showed the current profile as available. Instead, I took the route of right-clicking on Computer and going to Properties. From there, you click ‘Advanced system settings’. Under the ‘Advanced’ tab, a section for User Profiles has a ‘Settings…’ button. This opens the User Profiles window and I could see the other local accounts.

Click on the Default Profile and click the ‘Copy To…’ button. In the dialog that pops up, choose a location to save the file and under Permitted to use click ‘Change’ and type ‘Everyone’. Click OK on that dialog and the Copy To dialog to copy the profile.

You now have a profile that can be used for the Creating a Mandatory User Profile article. Browse to the profile’s copy to location that you chose in Windows Explorer. Hit the Alt key to see the menu bar and go to Tools, Folder options. Uncheck the box ‘Hide protected operating system files’ and hit Ok to close the dialog boxes. You should now see an ntuser.dat file in Explorer. This is the equivalent to the HKEY Current User in the registry. Rename the file from ntuser.dat to ntuser.man. Go up a level in the folder structure and rename the profile folder to [anything].v2.

There’s your mandatory profile. You can assign it through Active Directory Users and Computers and continue setting up the user experience.

Filed Under: System Administration

Trending

  • Holiday shopping e-commerce [infographic]
    In Infographics, Media
  • A robot adventure unfolds in 404 Not Found: A Coloring Book by The Oatmeal
    In Featured, Hardware, Gadgets, and Products
  • AccessChk – Permissions Reporting Utility
    In Code, Security and Privacy, Software, System Administration, Tech Solutions

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • Access to the resource [servershare] has been disallowed Access to the resource [servershare] has been disallowed
  • Read the Event Logs on Windows Server Core Read the Event Logs on Windows Server Core
  • Increase IIS Private Memory Limit to improve WSUS availability Increase IIS Private Memory Limit to improve WSUS availability
  • How to ‘Unblock’ multiple files at a time with PowerShell How to 'Unblock' multiple files at a time with PowerShell
  • Setup your DFS namespace with DNS for compatibility in a mixed environment Setup your DFS namespace with DNS for compatibility in a mixed environment
  • How Virtual Reality Supports Mental Health Therapy How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting
  • Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams
  • customer contactless payment for drink with mobile phon at cafe counter bar,seller coffee shop accept payment by mobile.new normal lifestyle concept The Latest Innovations In Payment Technology
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in