+ Post New Thread
Results 1 to 5 of 5
How do you do....it? Thread, Preventing saving to desktop on roaming profiles in Technical; I'm trying to implement desktop restrictions on staff roaming profiles but encountering a couple of issues. I've used XCACLS on ...
  1. #1
    Gibbo's Avatar
    Join Date
    Feb 2008
    Location
    Cheshire
    Posts
    907
    Thank Post
    207
    Thanked 344 Times in 238 Posts
    Rep Power
    93

    Preventing saving to desktop on roaming profiles

    I'm trying to implement desktop restrictions on staff roaming profiles but encountering a couple of issues.

    I've used XCACLS on the desktop folder in their server copy of the profile to prevent them from writing:

    Code:
    %LOGONSERVER%\Netlogon\xcacls "%USERPROFILE%\Desktop" /P "%USERDOMAIN%\%USERNAME%":RX Administrators:F System:F /Y
    and in Group Policy Admin Templates - Desktop I've enabled "Don't save settings at exit"

    But the problem is that when they're logged on they can still save stuff onto the desktop. Its only when they log off they get an error that the files cannot be written to the server location.

    Plus, when they log back onto the same machine the files are there because of the locally cached copy of the profile.

    Can anyone advise what other option I'm missing out? ISTR years ago when I first implemented this I could get an "Access denied" error whenever you tried to put something on the desktop.

    TIA.

  2. #2


    Join Date
    Mar 2009
    Location
    Leeds
    Posts
    6,593
    Thank Post
    228
    Thanked 856 Times in 735 Posts
    Rep Power
    296
    possibly easiest way is to redirect the desktop to a network location they only have read access to

  3. #3
    themightymrp's Avatar
    Join Date
    Dec 2009
    Location
    Leeds, West Yorkshire
    Posts
    1,204
    Thank Post
    212
    Thanked 223 Times in 192 Posts
    Rep Power
    72
    I'll second that, much easier way than setting permissions on a roaming desktop

  4. #4
    Gibbo's Avatar
    Join Date
    Feb 2008
    Location
    Cheshire
    Posts
    907
    Thank Post
    207
    Thanked 344 Times in 238 Posts
    Rep Power
    93
    Cheers guys I'll have a read at this thread, seems like a good idea.

  5. #5

    glennda's Avatar
    Join Date
    Jun 2009
    Location
    Sussex
    Posts
    7,810
    Thank Post
    272
    Thanked 1,135 Times in 1,031 Posts
    Rep Power
    349
    I think the way to do it would be to leave the server permissions fine and then setup a gpo which gives read only access to C:\docs&settings\%username%\Desktop

    then just ensure there is nothing on there desktop on the server. although you can't then deploy any shortcuts to the user profile

    T

SHARE:
+ Post New Thread

Similar Threads

  1. Preventing change to desktop background
    By theeldergeek in forum Mac
    Replies: 10
    Last Post: 18th May 2010, 12:23 PM
  2. Preventing users saving to temp files?
    By Tegwin in forum Windows
    Replies: 2
    Last Post: 8th March 2010, 11:59 AM
  3. Roaming Profiles...
    By richard_s in forum How do you do....it?
    Replies: 11
    Last Post: 31st July 2009, 08:19 PM
  4. Roaming Profiles
    By Shocker in forum Network and Classroom Management
    Replies: 10
    Last Post: 30th March 2009, 05:13 PM
  5. Roaming Profiles - help please
    By robbied69 in forum Windows
    Replies: 2
    Last Post: 25th September 2006, 05:13 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •