Plan your Profile Management Deployment First stage in planning is to decide on a set of policy settings that together form a configuration that is suitable for the environment and users. We suggest that you configure the policy only from one place. We recommend that you configure the common policies through GPO or Studio. Profile management is not supported with REFS file system.

Please watch the below video to get the advice from expert on Citrix Profile Management deployment methods. Edit configuration as per requirement. Install Profile Management. Profile Management. Plan your Profile management deployment. Create the user store. To specify the path to the user store. To enable Profile management. Enable logging for Troubleshooting CTX Migrate profiles? To configure folder redirection. Was this page helpful?

Or am I missing something? But we wanted a bunch of users to test the new settings in real life before rolling the settings out for all users. Would have been good if it was possible to define these settings on user group level. Hello Carl, I am struggling with user profiles and a huge amount of files in it. Mostly IE Cookies and Chrome. Although I actually set the mentioned recommended settings. Maybe any hints where I could optimize. Process Cookies at logoff is enabled.

Well Chrome is another headache for me. We use the profile. We are coping with very slow logoff times and the scheduled reboots configured in the delivery group does not work reliable as the Server then stays in off state. Thanks, Sergio! So simple yet so helpful. Our profiles appear to be frozen in time. No new changes are saved between sessions, but existing changes before the issue occurred are persistent.

New users that just came on the platform are having no changes being saved. The logs below show that it finds the profile in the users store and loads it up. DAT file and the settings are not saved back. It is quite bizarre. One article I read said that perhaps the machines are rebooting refresh on logoff before the profile can save back, but that has not been changed and it clearly tries to read the NTUSER.

Perhaps some sort of file locking issue. Windows updates to the image and standard stuff during that time. Console session. DAT for cross-platform processing during logoff. The system cannot find the file specified. It looks like the error message was coming from Active Write Back.

I disabled the setting and the errors have gone away in the logs, but the new profile settings are still not saving back to the user store. I am now looking at AV to see if it might be a culprit. DAT file appears to be locked by another process at logoff.

I have opened a case with Ctirix and will send an update when we find a solution:. We had a setting that was reported not being saved back by development, so we added the key there. This apparently disables all the default inclusions for the HKCU hive that is set by default you would have to add them all back in which is not feasible.

There is no information or description in the WEM console to know this, but if you go to the Citrix Policies and read the description on the setting it tells you there. Citrix was completely lost on this case including escalation — they thought it was a permissions issue and I had to figure this out myself though process of elimination. It was a literal needle in a haystack. The problem presented itself as something very different than a setting that would just exclude the HKCU hive preventing most settings from being written back to the user store.

I wanted to provide an update and hope this saves someone else the pain it caused us. There is a mistake in your post. I know this is working as we can see the users old files showing up when logging into the new Citrix session servers. Wondering if you might know how it knows the source location to pull old user profile from in the absence of this setting?

Roaming vs Local is based on what you see in sysdm. That would point to a UPM user store. I running XenDesktop 7. But homefolder data has been copied into the profile. This is configured in the policy in case of the GPO being removed. Strangely this only happens to some VDAs and with the next reboot and can be fine again on these and happen on others. Once a user logged in on VDA where the policy has been applied correctly, Data is moved out of the profile again.

Thanks for fast reply. Sorry, my fault. So it seems we have reboots where it works fine and then we have reboots where it does not apply User GPOs at all… Computer GPOs are getting applied though. I am not using the citrix profile manager for my user profiles so this one has not installed on my VDAs. Towards the end of the day it seems like things start to really slow down and we will find dozens if not hundreds of folks stuck logging off.

Anyhow, I guess my question is, what could I look at to possibly improve our situation and prevent the profile hangups from snowballing to whatever else is going on with the file server? We are using WEM to configure UPM and one thing I noticed is we have Profile streaming enabled, active write back for registry enabled, but not active write back. I keep reading conflicting stories about whether I should or should not enable write back. Just an update on this, we did migrate the profiles volume to its own file server.

While this has alleviated the latency on the rest of the shares, the slow logoffs still persist, so we only succeeded in isolating the problem a bit. Our environment is now on CU1, and we have once again reached out to Citrix. They are again suggesting that we try AWB. I know your blog says to turn it off due to impact on file server, which I brought up with Citrix, but they say that we should still try it though.

Some sources say the biggest potential impact would be in the mornings, when everyone is logging on. An example they gave is that if they all open up Internet Explorer soon after they log in, then it could potentially mean a burst of write back activity once they close it out, with the webcachev I think Active Write Back writes all changes to the file share as the changes occur throughout the day even if the same file changes multiple times throughout a day.

Yes, that is one understanding that I had of it as well. So in a profile container, you have a. Side note: We have recently started implementing FSLogix for a small group of single-session Win10 users. FSLogix is something I am interested in applying to all of our user base, but we have much more testing and fine tuning before we can really push for that change.

Carl I am reviewing VDA logs trying to learn what makes a successful logon and why some are not so successful. Starting logon processing… ; DAT The operation completed successfully. Citrix Profile Container has limitations. What is the problem? Is there any other things to check? You might have to do some policy settings to enable the log. Hey Carl very nice guide! The Logfile says that no upm policy is configured.

This affect on our users to not load the upm settings. As for the template profile i configured the template path on Citrix policy instead of user inheriting the default profile on the VDA. Question: would it cause any issues? Followed your guide thank you! Users can sign into Chrome and while in the session, it stays connected fine, but when signing out and signing back in, the Chrome login is lost and it starts on the Welcome to Chrome tab.

Everything has been configured as discussed above regarding Chrome. Sorry, forgot to add that we had this set of users on prior and it was working flawlessly, no GPO changes between the two. Gets really annoying. We have an issue where program defaults are not sticking or cannot be set and we cannot open the settings page. If we do the desktop side we can open it but the problem still exist with default programs not sticking.

For that session Chrome stays. Log off, wait a few minutes, log back on only one test server at this time so it is the same machine , open the same link as before and it has reverted back to IE. Looked at the registry values and the hash seems to be the key in breaking this. Thank you for this information. I have tried to follow the steps provided but it does not seem to work. IE still sits as the default program for opening web browsers.

That worked perfectly!!! Thank you very much for your time and advice on this. Do the newer Profile Management versions support creating the Desktop folder in the user profile on the server when opening a published application? Published Desktops server-based work fine and turning off Profile Management allows the Desktop folder to be created regardless of whether a published application or desktop is opened.

I assume this only applies to new users. Along with the whole user director shell. Unless you excluded it. Just make sure your not excluding it in the upm policy. Citrix Policies has settings for Folder Redirection. Try not to mix configuration options. Multiple Datacenters For optimum performance, users connecting to Citrix in a particular datacenter should retrieve their roaming profiles from a file server in the same datacenter.

The user has separate profiles for each datacenter — There is no replication of profiles between datacenters. This scenario is best for deployments where different applications are hosted in different datacenters. A datacenter failover might result in multiple file servers accessed from a single VDA, especially if you have users split across datacenters. Use DFS Namespaces as detailed below. Here is an overview of the configuration: Create a domain-based DFS namespace with folder targets on different file servers.

See Scenario 1 — Basic setup of geographically adjacent user stores and failover clusters at Citrix Docs for more information. Do not enable two-way DFS Replication for the roaming profile shares. But you can do One-way DFS replication. See Scenario 2 — Multiple folder targets and replication at Citrix Docs for more information. The folder that matches the attribute value is linked to a file server. The Omaha folder is linked to a file server in the Omaha datacenter.

Create User Store This procedure could also be used to create a file share for redirected profile folders. Create and Share the Folder Make sure file and printer sharing is enabled. On the file server that will host the file share, create a new folder and name it CtxProfiles or similar.

Click Share , and then click Done. Go to the Properties of the folder. On the Sharing tab, click Advanced Sharing. Click Caching. Select No files or programs. Click OK , and then click Close. On the Security tab, click Edit. For the Everyone entry, remove Full Control and Modify. Make sure Write is enabled so users can create new folders. This grants users Full Control of the folders they create. Click OK. Now click Advanced. Highlight the Everyone permission entry, and click Edit. Change the Applies to selection to This folder only.

Click OK three times. This prevents the Everyone permission from flowing down to newly created profile folders. Access Based Enumeration With this setting enabled, users can only see folders to which they have access: In Server Manager, on the left, click File and Storage Services.

Or perform a refresh. Right-click the new share and click Properties. On the Settings page, check the box next to Enable access-based enumeration. Copy the file ctxprofile. If you have an older version of the ctxprofile. Note: replacing the. The template only defines the available settings, not the actual settings.

Copy ctxprofile. This is a subfolder of the PolicyDefinitions folder. CitrixBase : Go up a folder and then open the CitrixBase folder. In the CitrixBase folder, copy the file CitrixBase. Note: if you did not install the CitrixBase. Enable the setting Enable Profile management. Profile Management will not function until this setting is enabled.

If desired, enable the setting Process logons of local administrators. Enable Path to user store. Specify the UNC path to the folder share. Profile Versions — Different OS versions have different profile versions. Each profile version only works on specific OS versions. For example, you cannot use a Windows 7 profile v2 on Windows 10 v6.

The variables in the path above ensure that every unique profile version is stored in a unique folder. If users connect to multiple operating system versions, then users will have multiple profiles. Windows 10 Profile Versions — Windows 10 has two different profile versions.

Windows 10 build and older use v5 profiles. Windows 10 build and newer use v6 profiles. Windows 10 v6 vs Windows v6 — Both Windows 10 and newer and Windows Server use v6 profiles. Do you want to use the same profile for both platforms? If so, remove! Note: Windows 10 supports Store apps while Windows does not. Windows R2 warning: in older versions of Citrix Profile Management,!

The profile version bug was fixed in Profile Management 5. If you have existing Windows R2 profiles based on the! Windows 10 and! Windows Server sets! Windows 10 version and set! Windows 10 version sets! If you use! Profile Management and newer have a setting called Automatic migration of existing application profiles under Profile Handling that can alleviate this problem. That way you can have the same account name in multiple domains and each account will have a different profile.

Hard Code Store Path — Instead of using variables, you can specify a hard coded path. However, the profile incompatibility restrictions listed above still apply. Migrate User Store — Profile Management and newer can move profiles from an old profile path to a new profile path.

Disable Active write back. This feature places additional load on the file server and is only needed if users login to multiple machines concurrently and need mid-session changes to be saved, or if users never log off from their sessions. On the left, go to the Advanced settings node. Enable the setting Process Internet cookie files on logoff.

It can be disabled here. Profile Management 7. Profile Management and newer support bit Outlook and Office VDA or newer are recommended for the bug fixes for this feature. Concurrent sessions on multiple machines are not supported. The template file is copied to new users, thus speeding up VHDX creation. The per-user. Modify permissions are not sufficient. Only enable this feature for users with new Outlook profiles. If the user already has an.

The Search roaming feature is only supported with specific versions of Windows Search service. Event Log will tell you if your Windows patches are too new. VHDX files can only be mounted on one machine at a time. Search Index Backup — Profile Management and newer have a GPO setting named Outlook search index database — backup and restore that can provide automatic recovery of the search index if it becomes corrupted.

The backup consumes more of the available storage space of the VHDX files. You can use checkboxes to not exclude some folders. Then edit Exclusion list — directories. Enable the setting, and click Show. Add the following to the list. The licensing tokens also last 30 days instead of days. James Rankin has a much longer list of exclusions and synchronizations at Everything you wanted to know about virtualizing, optimizing and managing Windows 10…but were afraid to ask — part 6: ROAMING.

Profile Management and newer automatically include usrclass. If added to the exclusion list, then Profile Management and newer automatically removes it from the exclusion list. See Start menu roaming at Citrix Docs. Clean up excluded folders — If you add to the exclusions list after profiles have already been created, Profile Management 5. See To enable logon exclusion check at Citrix Docs. In Profile Management 7. Edit the setting Directories to synchronize.

