I’ve been exploring the capabilities of the FSRM — specifically the File Screen Management feature — to see how it works and what it can do. To test it out, I set up in a lab with some VMs. I created a few dummy accounts in our domain, set them up with roaming profiles pointed to our file server, and then made a file screen to ping on NTUSER.DAT. The rule is very simple; it operates in passive mode so all it does is sends me an email whenever an NTUSER.DAT file gets created or modified. In theory, I should get a message every time one of my dummy accounts logs into (or more precisely, OUT of) a workstation.
I’m finding that it’s very inconsistent. To test the rule on the initial creation of the file, I would log in to a VM with a dummy account, log back out, and see that it creates the NTUSER.DAT file every single time (as it should). I then delete the profile off the server, revert the VM, and do it again. I did this dozens of times with 3 different accounts. FSRM usually gets triggered, but not always.
To see how it would behave on file modification (which is really what I was most curious about), I left three VMs signed in with the dummy accounts overnight with a group policy that configures them to sync the profile every hour. Over the course of 15 hours with 3 accounts signed in, I should’ve gotten 45 emails. I only got 6 or so. I know that NTUSER.DAT is being updated every hour because I can see the time stamp change. So FSRM far less consistent about modification than it is at file creation.
I’ve left those VMs running for several days now. I should be getting spammed with notification emails, but I’m not. They only trickle in at a rate of one every couple of hours on average, but even that is inconsistent. And again, if I delete the profiles, revert the VMs, and sign in/out again, I’ll get more notifications, but it’s still not 100%. I even set up a command line in the rule too that dumps an empty text file onto the drive just to make sure email wasn’t the problem. That part is 100% consistent. Every time I there’s an email, there’s also an empty text file. I never get just one or the other, so it’s definitely the rule not getting triggered and not a problem with emails getting blocked or whatever.
So what gives?