Cisco VPN and Folder Redirection

Desperate Dan 1 Reputation point
2020-07-21T17:02:25.647+00:00

Hello and hope everybody is keeping well in these difficult times.

Please could someone help with the following query.

Query Summary

How can we get folder redirection for desktop, documents, IE favourites etc to work when there are a large population of users using a Cisco VPN client.

Query background.

The reason for the question is that we will be migrating all our users to OneDrive and redirecting their folders from a network drive to OneDrive so their desktop folders, my documents, IE favourites will reside in OneDrive. The users network drive will then be removed.

The process to use the Cisco VPN client is such that users connect to the VPN after they have first logged into their laptops remotely. Subsequently they do not get Group Policy applied to them at the point of first logon.

Unless I am mistaken I do not think a GPUpdate /force works for folder redirection as the user has the folder redirection objects locked out by the fact that they are currently logged on.

If users were LAN connected (e.g. in an office we would not be having this issue)

We are in the early stages of researching this scenario and will be putting some test plans in place to overcome this which we will happily feed back here.

At present our only thoughts are to run a script locally on the users laptops to manually perform the folder redirection and then do a reboot but this is yet to be tested.

Any thoughts or insight to a solution would be greatly appreciated.

Maybe someone has had this issue before and has found a solution.

Many many thanks in advance for any input received.

Yours's gratefully.

Dan

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,478 questions
Windows Server PowerShell
Windows Server PowerShell
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.PowerShell: A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
5,546 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Fan Fan 15,341 Reputation points Microsoft Vendor
    2020-07-22T02:28:28.237+00:00

    Hi,

    In your situation, ,what's the result if you sign out and sign in again?

    Firstly, In situations where you need for users to implement folder redirection in a single logon, apply a GPO with the setting “Always wait for the network at computer startup and logon ”to the computer. This setting is located under Computer Configuration\Administrative Templates\System\Logon in the Group Policy Object Editor. Update the group policy and then confirm the result again.
    Also,based on my research, we need to connect VPN before login with our domain account.
    Then configure VPN to be connected before login with our domain account.
    Since don't have the Cisco VPN environment ,i'm afraid can't give more advice for the configuration.

    Similar case for your reference:
    https://social.technet.microsoft.com/Forums/en-US/b83b93a6-5663-4f56-95dd-057374cc37c8/apply-gpo-through-vpn?forum=winserverGP

    Best Regards,


  2. Soccan 16 Reputation points
    2020-08-13T12:03:25.63+00:00

    Can users make changes to the Cisco VPN config? Though my information is very outdated, this is Windows XP-era, one of the things I loved with the back then Cisco VPN client was that it was able to start before Windows logon.

    0 comments No comments

  3. Vzzzbucks 1 Reputation point
    2020-08-20T20:13:39.92+00:00

    I'm currently in the same situation but we're simply moving users' redirected folders from one file server to another, not to OneDrive.

    One option we are considering is to get users to remote onto RDS servers to initiate the process, as we're soon to roll out RDS across the company. Failing that, you could get the users to remote onto a workstation in the office which is connected directly to the LAN. Though not ideal, this should process the GPO at logon and move the files over.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.