多AD用户共享Home Folder/Profile及多凭据关联单账号的可行性咨询
Hey there, let's break down your two main questions one by one—this is a super common scenario in healthcare IT, so I’ve got some practical, tried-and-true solutions for you.
关于共享配置文件/主文件夹,实现同组用户自动同步设置的方案
First off, I think you might have misunderstood how mandatory user profiles can work at scale. If you store the mandatory profile in a centralized network share (instead of local machine profiles), you only need to update that single shared profile file once. Any user assigned to use this profile will automatically pull the updated settings on their next login. Just make sure the profile is marked as read-only (rename the NTUSER.DAT file to NTUSER.MAN) and that all users in your target group have read access to the share. This completely eliminates the need to manually tweak individual profiles one by one.
Beyond that, here are two more robust approaches tailored to your needs:
- Folder Redirection + Group Policy: For home folders and shared file access, redirect core user folders (Documents, Desktop, Favorites) to a centralized network share via Group Policy. You can configure permissions so all users in the role-based group have access to the same shared files. To avoid file naming conflicts, set up user-specific subfolders within the shared location, while also having a dedicated "Common Resources" subfolder that everyone can access and modify.
- Group Policy Preferences (GPP) for uniform settings: Instead of relying on profiles to enforce software updates, printer mappings, or application configurations, use GPP to deploy these settings directly to the group. You can push printer connections, set registry keys for software defaults, or add shortcuts to shared applications—any changes you make to the GPP will automatically apply to all group members on their next login or policy refresh (no profile updates required).
关于多凭据关联单个用户账号的可行性
Short answer: This isn’t feasible (and is a massive security/compliance red flag) in Active Directory. Each AD user account is tied to a unique identity, so sharing one account across multiple users means you can’t track individual activity, password resets will disrupt everyone, and you’ll run into huge compliance issues—especially in healthcare, where audit trails are non-negotiable.
Instead, use security groups to achieve your goal without shared accounts:
- Create a role-based group (e.g., "MedicalClinicStaff") and add all relevant users to it.
- Assign permissions for shared applications, files, and printers directly to this group, not individual users.
- This way, you manage access at the group level—new users get access automatically when added to the group, and you don’t have to juggle messy shared profiles or accounts.
If you still need user-specific settings to follow them between devices, combine group-based GPP with roaming profiles: Roaming profiles sync user-specific data to a server, while GPP enforces the uniform settings that need to stay consistent across the entire group.
Hope that clears things up—let me know if you need help with specific GPO setup steps or profile configuration details!
备注:内容来源于stack exchange,提问作者gorokizu

