Use these advanced FlexEngine settings to configure Dynamic Environment Manager in specific scenarios.
These settings can be configured using the Advanced Settings ADMX template attached to the Knowledge Base Article KB 2145286.
Note: To configure Group Policies for FlexEngine advanced configuration, use Active Directory GPO instead of ADMX-based settings configured from the DEM Management Console.
| Setting | Description |
|---|---|
| Allow processing ADMX-based settings, Application Blocking, Horizon Smart Policies and Privilege Elevation configuration during a session | Enable this setting to allow DEM to revert ADMX-based settings, application blocking, and Horizon Smart Policies and Privilege Elevation configuration if a DEM export is triggered during a session. By default, DEM reverts these settings only during logoff to prevent security issues.
Note: Changing the default behavior has a security impact, as it allows users to circumvent restrictions. |
| Symantec Endpoint Protection DirectFlex export fix | Enable this setting if DirectFlex exports are not being performed on clients where Symantec Endpoint Protection is running. |
| Compatibility fix for Sophos EndPoint Protection | Certain versions of Sophos Endpoint Protection can affect DEM functionality. Enable this setting to solve the issue. |
| Compatibility fix for Omnissa Horizon PCoIP smartcard redirection | Certain DEM functionality can prevent the PCoIP smartcard redirection feature of Omnissa Horizon Agent 7.1 or newer from functioning correctly. Enable this setting to solve the issue. |
| Disable DirectFlex | Enable this setting to disable the DirectFlex. This setting can be used to migrate Omnissa Persona Management to Omnissa Dynamic Environment Manager. For more information, see Migrate Persona Management to User Environment Manager (2118056).
There are two options for this setting:
|
| Environment variable prefix | Enable this setting to configure another prefix than 'UEM' for the %UEMSessionID%, %UEMConfigShare% and %UEMScripts% environment variables. |
| Global excludes | Enable this settings to apply global exclusions across all Flex config files. Specify the absolute or relative path to your global excludes Flex config file here. If a relative path is specified, it is resolved against the General folder. |
| Custom commands | Enable this setting to run a custom command before or after the DEM agent performs a path-based import or path-based export. |
| Custom commands as SYSTEM | Enable this setting to run a custom command in SYSTEM context before or after the DEM agent performs a path-based import or path-based export. |
| Printer mapping | Enable this setting to perform the specified number of retries when mapping and unmapping network printers. Ensure to map printers asynchronously to minimize the impact on login times. |
| Remove local profile at logoff |
Note: All settings and user data stored in the user profile are deleted.Enable this setting to let Windows remove a local profile at logoff.
To skip removal of local profile at logoff for certain users or devices, specify a comma-separated list of group names. For example, Do not apply if user is a member of: UserGroup1,UserGroup2
Do not apply if device is a member of: DeviceGroup1,DeviceGroup2,DeviceGroup3
To skip removal of local profile at logoff for members of the local administrators group, enable Do not apply to members of the local administrators group. Note: Enabling this feature can impact the logoff performance in some scenarios like multi-user (RDSH). |
| DirectFlex compatibility fix for BeyondTrust and Avecto | In some scenarios, enabling DirectFlex could stop the privilege elevation functionality with certain versions of BeyondTrust PowerBroker and Avecto Privilege Management. Enable this setting to solve the issue. |
| Special Drive Mapping Logic | Enable this setting to activate a special drive mapping logic that can solve drive mapping issues if users can have multiple concurrent sessions on the same host. |
| Disable DEM Agent Features | Enable this setting to disable specific DEM agent features, either completely or only during login. |
| Validate .REG file | Enable this setting to log additional diagnostic information when import of .REG file fails. |
| Diagnostics: Enable verbose logging for ADMX-based settings, application blocking, Horizon Smart Policies and Privilege Elevation | Enabling this setting creates an additional log file in the same location as the FlexEngine log file. This additional log file will contain debug logging information for the DEM features ADMX-based Settings, Application Blocking, Horizon Smart Policies and Privilege Elevation. |
| Diagnostics: Collect performance log | Enable this setting to collect a binary performance log while DEM is performing a path-based import. This log can subsequently be viewed and analyzed in Windows Performance Monitor. |
| Diagnostics: Log CPU and I/O statistics | Enable this setting to log CPU and I/O statistics. |
| Diagnostics: Log CPU consumption | Enable this setting to log CPU consumption of other processes that were running while DEM performed a path-based import or export. CPU usage is logged for each process that consumed more CPU than the configured threshold (in milliseconds). |
| Diagnostics: Log slow calls | Enable this setting to configure how long certain calls can take (in milliseconds) before a warning is logged. |
| DFS namespace support for application blocking (requires DEM 2111 or later) | Paths configured for application blocking referencing a DFS namespace might not be processed correctly on some combinations of client OS and file server OS. Enable this setting to have DEM also add the resolved target locations to the in-memory configuration. |
| Folder redirection (requires DEM 2111 or later) | By default, FlexEngine will undo folder redirection settings at logoff, and will let Windows initialize the target folder to enable folder name localization. If original folder locations cannot be determined (often due to overzealous optimizations of the default Windows user profile), folder redirection will fail. If undo is not required (in non-persistent setups, for instance), it can be disabled. Target folder initialization sometimes fails. If localization of folder names is not required, it can be disabled. |
| Multiple concurrent sessions (requires DEM 2111 or later) | If users can have multiple concurrent sessions on the same host, these sessions will share a single Windows user profile. This means that DEM's path-based import at logon should only take place for the first session, and the path-based export at logoff should only be performed when the user logs off from their last session. This is the default behavior. Disabling this policy setting will result in path-based imports and exports for each session. In Horizon environments, the default multi-session behavior is to apply Horizon Smart Policies in every session. |
| Only perform path-based export (requires DEM 2111 or later) | For certain migration scenarios, it can be helpful to have the DEM agent only perform path-based exports. If you need that behavior, enable this setting. |
| Override existing user policy settings (requires DEM 2111 or later) | By default, FlexEngine does not overwrite existing information in the policy registry locations. If you use Dynamic Environment Manager ADMX-based user settings with Active Directory group policies and configure overlapping user policy settings, the Active Directory settings take effect. The same applies for policy settings that are part of a default user profile. Enable this policy setting to allow ADMX-based user settings to override existing user policy configuration. |
| Silo-specific Flex config files | Enter an additional, silo-specific path for Flex config files to be processed in addition to the general Flex config files path. The silo-specific suffix is used as a subfolder of the configured profile archive path, to separate profile archives for silo-specific Flex config files from general ones. If no silo-specific suffix is configured, the last component of the silo-specific Flex config files path is used. |
| Process environment variable settings before folder redirection (requires DEM 2203 or later) | By default, DEM folder redirection settings are processed before DEM environment variable settings. Enable this setting to process environment variables settings before DEM folder redirection settings. |
| Override previously hidden drive letters (requires DEM 2203 or later) | By default, Hide Drives Settings are merged with any drive letters that were already hidden through other configuration. Enable this setting to override the existing Hide Drives Settings. |
| Use built-in registry parser (requires DEM 2206 or later) | Use the built-in registry parser instead of regedit.exe or reg.exe to import registry settings. |
| License location (requires DEM 2206 or later) | By default, the DEM agent finds its license in the General\FlexRepository\AgentConfiguration\License.xml file on the config share.
Enable this setting to specify a different location as the fully-qualified absolute path of the license file.
For example, the license file location can be similar to C:\Users\test1\Desktop\License.xml. |
| Disable import and export (requires DEM 2209 or later) |
Enable this setting to disable the import and export functionality for certain users or devices, specified by a comma-separated list of group names.
For example, Disable import and export if user is a member of: UserGroup1,UserGroup2
Disable import and export if device is a member of: DeviceGroup1,DeviceGroup2,DeviceGroup3 |
| Secondary logging on Horizon (requires DEM 2312 or later) |
Enable this setting to specify a different maximum size for secondary logging on Horizon.
For example,
Maximum log file size in kB: 1024.
By default, the secondary log files are recreated when they reach a size of 512 KB. To disable creating secondary log files, set the maximum size to 0. |
| Delegate pending DirectFlex exports to child process (requires DEM 2312 or later)
Timeout in seconds |
If a DirectFlex import for an App-V 5 application has taken place during the session, logoff processing of pending DirectFlex exports is delegated to a child process by default. This prevents issues that might occur when performing an App-V 5 export during logoff.
Enable this setting to always delegate pending DirectFlex exports, regardless of whether an App-V 5 import was performed during the session. Disable this setting to never delegate pending DirectFlex exports (this might cause pending App-V 5 exports to fail). By default, the overall DEM logoff processing waits for 120 seconds to complete the delegated export. This timeout can be modified by configuring Timeout in seconds.
|
| Ignore computer name for run-once flag files (requires DEM 2412 or later) | This setting is applicable only when the Run Once option is enabled for the user environment settings.
When you enable this setting, the DEM agent checks if any flag file exists for a user environment setting, regardless of the computer name. If the flag file already exists for the user, a "fallback" flag file will not be created. Note: This setting has a similar behaviour compared to the existing runOnceSpecial="1" attribute. However, if you are using the runOnceSpecial attribute, it creates a "fallback" flag file based on the computer name.
|
| DirectFlex compatibility fix: Change process exit logic (requires DEM 2412 or later) | In certain cases, DirectFlex logic might interfere with the exit of DirectFlex-enabled UWP apps. As a result, no DirectFlex export is performed at that time, as the process does not fully exit.
Enable this setting to change the process exit logic. |
| Use workaround for default applications and file type associations (requires DEM 2503 or later) | Previously, a separate configuration for the UCPD.sys workaround was required to correctly process default application settings and file type associations. Starting with Dynamic Environment Manager 2503, the workaround logic is incorporated into the product to provide a seamless and reliable solution for managing default browser and PDF FTA settings on Windows systems. By default, this feature is enabled.
Disable this setting to revert to the original behaviour. |
Was deze pagina nuttig?