Advanced account settings in user creation templates
In ADManager Plus, User Creation Templates let administrators preconfigure and standardize Active Directory user attributes for efficient provisioning. The Account tab of these templates allows you to define advanced account settings such as logon hours, profile path permissions, home folder permissions, and UAC properties.
Templates can be applied during single or bulk user creation, helping maintain consistency and reduce errors.
How it works
The Account tab of User Creation Templates in ADManager Plus allows administrators to predefine additional account-related settings that are applied automatically when new user accounts are created.
When an administrator creates or modifies a user creation template, they can configure advanced account settings such as logon restrictions, password-related options, account expiration, profile path, and home folder within the Account tab. Once the template is saved, users created using the template automatically inherit these predefined settings.
Prerequisites
- The logged-in user must be an ADManager Plus administrator or a help desk technician with the required permissions.
- Target Active Directory domains and Microsoft 365 tenants must be added and configured in ADManager Plus.
Set profile path permissions
Profile paths define where the user's roaming profile is stored. You can set permissions and options such as creating the directory before first login.
Steps to configure profile path:
- Under the Account tab of User Templates, navigate to the field Profile Path and enter an appropriate profile path.
- Click on Permissions to open a window for profile path settings.
- Check the Create profile path directory before user's first login box and add the required permissions using Add More Permissions.
- This leads you to set of options where you can allow/deny a selected user/group/computer permissions like Full Control, Read Attributes, Delete etc, over a folder and its descendants.
- If needed, check the Inherit (from parent) the permission entries that apply to child objects' option. Include these with entries explicitly defined here box.
You can also create a Windows Vista profile for your users by either:
- Selecting Create Vista(V2) Profile option located in the Profile Path Settings window that pops up when you click the Permissions link beside the Profile Path field, or:
- Suffixing the profile path with .V2. That is, if the normal profile path is C: \Documents and settings\Jim, the profile path for Vista profile should be C: \Documents and settings\Jim.V2. V5 and V6 profiles are supported as well.
Set home folder permissions
Home folders make it easier for an administrator to back up user files and manage user accounts by collecting the user's files in one location. If you assign a home folder to a user, you can store the user's data in a central location on a server, and make backup and recovery of data easier and more reliable. ADManager Plus has provided some special features that helps in quickly configuring these properties for the user.
Steps to configure home folder:
- Under the Account tab of User Templates, navigate to the field Home folder.
- Choose Connect and specify a drive letter. In the field nearby, type a path. This path can be any of the following types:
- Network path, for example: \\server\users\tester
- You can substitute username for the last subfolder in the path, for example: \\server\users\%username%
- Where server is the name of the file server housing the home folders, and where users is the shared folder.
- The "%username%" will automatically get expanded to the user's name.
You can also create a shared folder as users' home directory using ADManager Plus by checking the Create a New Share box. To make this new share as the users' home directory, use this format: \\server\%username% in the home directory path. Use the permissions link to set the desired permissions for this folder.
Customize basic UAC options
In the Account Properties field group, you can choose to configure options like User must change password at next logon, User cannot change password, Password never expires, and Account is disabled. You can also customize the options to display only the required options. Mentioned below are the steps to customize this grouping.
- Select the appropriate User Template.
- Click Enable Drag-and-Drop and navigate to the Account tab.
- In the Account Properties field group, hover over the listed attributes.
- Click on Edit from the options listed when you hover over the edit icon.
- In the Edit Basic UAC Options window that pops up,
- Hover over each of the UAC option/attribute. If it is currently visible, you will see the Hide link beside it and you will see a Show link if it is currently hidden. As per your need, you can choose to hide or show the option.
- Click Done to save the changes.
Customize account expiration
In the Account Properties field group, you can choose to configure when an account expires. You can either select a value from the drop-down list or enter a custom number of days by choosing Custom from the drop-down.
Steps to configure account expiration:
- Select the appropriate User Template.
- Click Enable Drag-n-Drop and navigate to the Account tab.
- Under the field group Account Properties, hover over Account Expires and click Edit from the options listed when you hover over the edit icon.
- Click Change Format to configure the preferred date and time format.
- Check the Restrict selection of 'Never' box to restrict users from choosing Never from the drop-down.
- Click Done to save the changes.
Configuring Logon Hours
You can specify the appropriate hours during which a user must be allowed access or restricted from accessing the domain using the Logon Hours option.
Steps to configure logon hours:
- Select the appropriate User Template.
- Click Enable Drag-n-Drop and navigate to the Account tab.
- Hover over the field Logon Hours and click Edit from the options listed when you hover over the edit icon.
- Click Select hours and enter the logon time frame in the From and To field.
- Choose specific days or all days of the week by checking the respective boxes to apply the chosen logon timings.
- Click Allow or Deny to grant or restrict users permission to logon to the network in the chosen time frame.
You can alternatively set logon hours by,
- Selecting each hour manually from the grid.
- Clicking the Allowed option to provide round the clock logon privilege from Sunday through Saturday and by clicking Denied to block out a user on all the days of the week.