Skip to content
ShabazTech

Notes of an IT Pro

ShabazTech

Notes of an IT Pro

  • Microsoft Azure
    • Compute
    • Governance
    • Identity
    • Networking
    • Security
    • Storage
  • Microsoft Entra ID
    • Identity
      • Application Management
      • Governance
    • Security
      • Authentication
      • Conditional Access
    • Global Secure Access
      • Internet Access
      • Private Access
  • Microsoft Intune
    • Apps
      • Microsoft365 Apps For Enterprise
    • Devices
      • Windows Clients
    • Monitoring
    • Security
  • Microsoft 365
    • Defender XDR
    • Purview
  • Microsoft OnPrem
    • AD DS
    • Failover Clustering
    • Hyper-V
    • Powershell
    • SQL Server
      • SQL Server 2008R2
      • SQL Server 2012
      • SQL Server 2016
    • System Center Configuration Manager
      • SCCM 2012R2
    • Windows Clients
    • Windows Server
      • Windows Server 2008R2
      • Windows Server 2012
      • Windows Server 2012R2
      • Windows Server 2016
  • Citrix
    • XenApp 6.5
    • XenApp and XenDesktop 7.6 LTSR
    • XenApp and Xendesktop 7.15 LTSR
  • About The Author
  • Microsoft Azure
    • Compute
    • Governance
    • Identity
    • Networking
    • Security
    • Storage
  • Microsoft Entra ID
    • Identity
      • Application Management
      • Governance
    • Security
      • Authentication
      • Conditional Access
    • Global Secure Access
      • Internet Access
      • Private Access
  • Microsoft Intune
    • Apps
      • Microsoft365 Apps For Enterprise
    • Devices
      • Windows Clients
    • Monitoring
    • Security
  • Microsoft 365
    • Defender XDR
    • Purview
  • Microsoft OnPrem
    • AD DS
    • Failover Clustering
    • Hyper-V
    • Powershell
    • SQL Server
      • SQL Server 2008R2
      • SQL Server 2012
      • SQL Server 2016
    • System Center Configuration Manager
      • SCCM 2012R2
    • Windows Clients
    • Windows Server
      • Windows Server 2008R2
      • Windows Server 2012
      • Windows Server 2012R2
      • Windows Server 2016
  • Citrix
    • XenApp 6.5
    • XenApp and XenDesktop 7.6 LTSR
    • XenApp and Xendesktop 7.15 LTSR
  • About The Author
Close

Search

Subscribe
Active DirectoryMicrosoftWindows ServerWindows Server 2008R2

Mapping Drives with Group Policy Preferences

By Shabaz
April 15, 2014 5 Min Read
2
Updated on March 14, 2016



Group Policy preferences is a feature that was included with Server 2008, and has been a part of Windows Server ever since. In this blog post, we will look at how to map drives through Group Policy Preferences and item-level targeting. The advantage of using Group Policy preferences is that you can target these drive maps to groups for example. Which means that only members of certain group(s) will get these drives mapped to a drive letter. You accomplish this by using item-level targeting.

Back in the day, pre GP preferences, if you wanted to map drives, based on group membership, you had to utilize logon scripts. With Server 2008 and newer, this has been changed. Now you can map drives through preference items, which can also apply to XP users, if you install GPO preferences extensions on the XP machines. But really, you should have migrated away from Windows XP by now. So let’s just concentrate on the most prevalent combination of server/client operating systems today, Server 2008 R2 and Windows 7.

1. CRUD – Create, Replace, Update, Delete

There are four type of actions that can be associated with a group policy preference item, these define how the preference item will be implemented. There are also different colors and icons associated with these four action types. So if you see a red triangle on your preference item, don’t be alarmed, its completely normal. 🙂

crud

Create – If a drive mapping does not already exist, it is created. If it already exists, nothing occurs.

Replace – If a drive mapping does not already exist, it is created. If it already exists, it is replaced with the one you have defined in your preference item (settings are also replaced).

Update – If a drive mapping does not already exist, it is created. If it already exists, its conflicting settings will be replaced with the ones you have defined in your preference item. If there are non-conflicting settings, they will be kept.

Delete – If a drive mapping exists on the specified drive letter, remove it.

CRUD can only be applied on preference items that can be created or deleted on the client machine/user account. Such as Drive Maps, Local Users or Groups items for example. You can not apply CRUD to Folder options or Power options for example.

Help Text for CRUD in Windows Help and Support for Server 2008 R2
preferences 

2. Creating Drive Maps through GP preferences

Drive maps is a user setting, so you will find the Drive maps setting in the User Configuration portion of a GPO. Complete path to the setting is as following

User Configuration → Preferences → Windows Settings → Drive Maps

2.1 Right Click Drive Maps → New → Mapped Drive
preferences2

2.2 The New Drive Properties appear
preferences3

Action – Choose among Create, Replace, Update or Delete

Location – The location of the network share, this field accepts preference processing variables. Press F3 to display the list of available variables. To modify the settings of an existing drive mapping (identified by drive letter), leave this field blank.

Reconnect – Equivalent to mapping a drive using the /PERSISTENT attribute.

Label as – Provide a descriptive label that will appear next to the drive letter.

Connect as – The drive map will use these credentials instead of the logged on user’s when you connect to it.

Hide/Show this drive – Choose to hide or show the drive in Windows Explorer.

2.3 Fill in the fields as you see appropriate, and then click on the Common tab
2.4 Choose Item-level targeting, and then click on Targeting
preferences4

2.5 Click on New Item and select Security Group
preferences5

2.6 Browse for the group, which members you want to map this drive to, if you like you can browse for more groups than one, in this screenshot, the drive will only be mapped if the user is member of both the Sales AND the Data group, otherwise it will not
preferences6

2.7 By clicking Item options, you can change the AND to OR if you like
preferences7

2.8 Now the drive will be mapped if the user is either a member of Sales OR Data
preferences8

2.9 Click OK twice, and you are done.
preferences9

2.10 You don’t have to use Groups for item-level targeting, you can, as you saw in step 2.5, select from a whole slew of items. Such as even computers or OUs. If you would like certain users to receive a drive map every time they log on to a specific computer, you can define it here, instead of using Group Policy loopback processing.

Additional Resources:
Technet: Group Policy Preferences Getting Started Guide
Technet: Configure a Mapped Drive Item
Technet: CRUD explained
Technet: Troubleshooting the Drive Maps Preference Extension in Group Policy

Tags:

Active DirectoryMicrosoftServer 2008R2Windows Server
Author

Shabaz

Follow Me
Other Articles
Previous

Migrate File Server from Server 2003 to 2008R2 or 2012

Next

Installing Clustered DHCP Server on Windows Server 2008 R2

2 Comments
  1. David says:
    March 25, 2017 at 14:24

    It’s a shame you don’t have a donate button! I’d certainly donate to this excellent blog!

  2. Brittany says:
    February 6, 2019 at 06:31

    It’s a pity you don’t have a donate button! I’d definitely donate to this brilliant blog!

Comments are closed.

Archives

Tags

Active Directory Citrix Failover Clustering Microsoft Powershell SCCM SCCM 2012R2 Server 2008R2 Server 2012 Server 2012R2 Server 2016 SQL Server Symantec VSF Test Labs Windows Clients Windows Server XenDesktop 7.6 LTSR Xendesktop 7.15 LTSR

Popular Posts

  • How to check if a machine is physical or virtual
  • Exporting multivalued attributes with Export-CSV cmdlet
  • Installing Remote Desktop License Server on Windows…
  • Configuring Remote Desktop Services Profile settings…
  • Installing Citrix XenApp and XenDesktop 7.15 LTSR
  • Enabling LDAPS with certificate from a 3rd party CA
  • Assigning ownership of files and folders with Takeown.exe
  • Retrieving User properties from Active Directory
  • SCCM 2012 R2 Client Installation
  • Citrix XenApp 6.5 Architectural Components
© 2014- 2026 — ShabazTech. All rights reserved.