# Keep roaming-profile storage separate from redirected-folder shares

> How should the storage location and user scope for roaming profiles be prepared?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-055-keep-roaming-profile-storage-separate-from-redirected-folder-shares/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:16:16+00:00
- Modified: 2026-09-08T18:20:21+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

How should the storage location and user scope for roaming profiles be prepared?

## Potentially affected

Use this review when deploying traditional roaming profiles to a defined client population.

## DSE recommendation

Prepare a storage-and-policy map showing the profile share separately from any redirected-folder share.

## Article

## Source facts

Roaming user profiles place profile data on a file share so users can receive operating-system and application settings on multiple computers. Microsoft’s deployment procedure creates a security group for the users or computers receiving the profile policies. It calls for a profile share separate from redirected-folder shares to avoid inadvertently caching the roaming-profile folder. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/storage/folder-redirection/deploy-roaming-user-profiles).

## Applicability

Use this review when deploying traditional roaming profiles to a defined client population. Identify the client versions, user group, share owner, and existing Folder Redirection configuration. Review version-specific profile requirements before the deployment.

## DSE recommendation

Prepare a storage-and-policy map showing the profile share separately from any redirected-folder share. Ask the desktop owner to approve the pilot users and application-settings tests. Verify the planned share permissions through the documented procedure and preserve the existing profile arrangement. Define how support will handle an incomplete first sign-in or an unexpected profile location.

## Verification

Test a pilot user on the intended computers and record the profile path and application settings observed. Inspect whether the approved policy scope and share separation are in place. Include a user outside the pilot scope. Resolve unexpected caching, profile placement, or missing settings before extending the deployment to more users.

## Official references

[Microsoft Learn: Deploy roaming user profiles](https://learn.microsoft.com/en-us/windows-server/storage/folder-redirection/deploy-roaming-user-profiles). Source reviewed September 8, 2026.

## Primary reference

- Name: Deploy roaming user profiles
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/storage/folder-redirection/deploy-roaming-user-profiles
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Keep roaming-profile storage separate from redirected-folder shares,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-055-keep-roaming-profile-storage-separate-from-redirected-folder-shares/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
