Skip to main content

24 luglio 2026

Configure the Dynamic Environment Manager Group Policy Object

After you create a Dynamic Environment Manager GPO, you must configure its settings. These settings are required to configure the location of the Dynamic Environment Manager configuration and profile archives shares, and configure FlexEngine to start automatically during login.

Prerequisites

You must at least configure the following settings:

  • Flex configuration files.
  • Profile archives.
  • Run FlexEngine at logon and logoff.

The rest of the Dynamic Environment Manager GPO settings are optional and enabling them depends on your infrastructure and requirements.

Note: The Always wait for the network at computer startup and logon computer Group Policy setting is no longer a mandatory requirement for Dynamic Environment Manager. However, in some scenarios, the infrastructure setup might need this policy to be enabled. As a best practice, enable the Always wait for the network at computer startup and logon setting for an OU in Active Directory where all the Windows clients are located.

  1. Open the Dynamic Environment Manager Group Policy Object
    To configure Dynamic Environment Manager, you must edit the settings of the Dynamic Environment Manager GPO that you created. Open the settings of the GPO from the Group Policy Management Editor. The Dynamic Environment Manager GPO configures FlexEngine with the correct Dynamic Environment Manager share locations and is therefore a required step.
  2. Configure the Flex Configuration Files Setting
    You configure the location of the central share that stores the Flex configuration files in the Flex config files setting. Flex configuration files contain Dynamic Environment Manager data that FlexEngine uses to read and store user settings. FlexEngine runs with the user's credentials, and processes each Flex configuration file for which the user has NTFS read access.
  3. Configure Run FlexEngine at Logon and Logoff Setting
    Run the FlexEngine when a user logs on to apply the settings and set up the environment, and save the settings at logoff.
  4. Configure FlexEngine Logging Setting
    You can configure the location and file name of the FlexEngine log file, the level of logging detail, and the maximum size of the log file.
  5. Configure Profile Archives Setting
    Configure the location of the profile archives share from where FlexEngine reads and stores user profile archives and other settings that are related to the profile archives.
  6. Configure Profile Archive Backups Setting
    Use the Profile Archive Backups setting to configure the location where FlexEngine stores the backups of profile archives.
  7. Configure Application Blocking Logging to the Windows Event Log Setting
    You can enable Application blocking logging to the Windows event log to have the details on blocked application launches logged to the Windows event log.
  8. Configure Privilege Elevation Logging to the Windows Event Log Setting
    You can configure Dynamic Environment Manager to log the details of elevated application launches and, if desired, de-elevated child processes.
  9. Configure Certificate Support for Mandatory Profiles Setting
    You can enable the use of personal certificates in a mandatory profile. In addition to enabling this support, you also must create a Flex configuration file with the Personal Certificates Windows Common Setting.
  10. Configure DirectFlex - Advanced Settings
    You can configure advanced DirectFlex settings for more fine-grained control over DirectFlex export settings and visual feedback.
  11. Configure FlexEngine Logging to the Windows Event Log Setting
    Use FlexEngine logging to the Windows Event Log to configure the events that FlexEngine logs to the Windows event log. When this setting is enabled, FlexEngine logs informational messages to the event log indicating the start and finish of path-based import and export actions.
  12. Configure Paths Unavailable at Logon Setting
    You can configure Paths Unavailable at Logon to determine the behavior if the Flex configuration files path or profile archives path is unavailable at login.
  13. Configure Access to DEM Self-Support for End Users
    You can control whether users have access to Dynamic Environment Manager Self-Support.
  14. Configure DEM Self-Support to Allow Reset of Multiple/All Profile Archives
    You can control whether the DEM Self-Support tool can allow reset of multiple or all applications to default settings.
  15. Configure Printer Mapping Timeout Setting
    You can configure the time that FlexEngine must wait to complete the printer mapping process, and select an action to either terminate the mapping or continue in the background (optionally at a lower priority) when the mapping times out.

Questa pagina è stata utile?

Invia un feedback su questo argomento

Questo argomento è stato utile?

Non includere informazioni personali o riservate.

Generazione del link…