I don’t see how this is a fog issue…
but I create a default profile too. But I don’t do it per machine.
I create a default profile and stick it in a secured SMB/UAC shared folder - and I have startup scripts that copy down the profile to a host locally, and then make necessary registry & permissions edits and install the default profile.
I have a scheme I use to push a new default profile anytime I want to every machine in the building. It’s totally custom - but I’d be willing to share my documentation on it.
