+ Post New Thread
Results 1 to 10 of 10
Network and Classroom Management Thread, Forbidding users to save files to desktop. in Technical; Good Afternoon ladies & gents. I was wondering if there was such a policy we could send out to our ...
  1. #1

    Join Date
    Jun 2009
    Location
    Watford
    Posts
    552
    Thank Post
    173
    Thanked 38 Times in 36 Posts
    Rep Power
    30

    Forbidding users to save files to desktop.

    Good Afternoon ladies & gents.

    I was wondering if there was such a policy we could send out to our teachers that forbids any files being saved to their desktop forcing to their docs area, but allow shortcuts to installed programs through? Had a brief look through the microsoft spreadsheet, but nothing jumps out at me

    Any ideas on this one gang?

    Andy T

  2. IDG Tech News

  3. #2
    danrhodes's Avatar
    Join Date
    Sep 2008
    Location
    Wath Upon Dearne
    Posts
    1,510
    Thank Post
    157
    Thanked 181 Times in 150 Posts
    Rep Power
    63
    Why not use GP to redirect the Desktop to one central location on the server, apply NTFS ACL permissions to that folder so that staff can only read, this way you have controll over what is on their desktop from one central location, all the program shortcuts can either go on the desktop of a seperate re-directed startmenu.

    1. Edit user GPO
    2. Go to user config
    3. Go to folder redirection
    4. Right click folder redirection and click properties.
    5. Redirect all to same location
    6. Create a folder on your server, share is as "Desktop" and apply NTFS ACL's to give staff read permission.
    7. Enter the address into the location as \\servername\desktop
    8. Sit back and relax.

    D
    Last edited by danrhodes; 26th May 2010 at 04:00 PM.

  4. Thanks to danrhodes from:

    andyturpie (28th May 2010)

  5. #3
    ICT_GUY's Avatar
    Join Date
    Feb 2007
    Location
    Weymouth
    Posts
    2,217
    Thank Post
    592
    Thanked 278 Times in 199 Posts
    Rep Power
    98
    Quote Originally Posted by danrhodes View Post
    Why not use GP to redirect the Desktop to one central location on the server, apply NTFS ACL permissions to that folder so that staff can only read, this way you have controll over what is on their desktop from one central location, all the program shortcuts can either go on the desktop of a seperate re-directed startmenu.

    1. Edit user GPO
    2. Go to user config
    3. Go to folder redirection
    4. Right click folder redirection and click properties.
    5. Redirect all to same location
    6. Create a folder on your server, share is as "Desktop" and apply NTFS ACL's to give staff read permission.
    7. Enter the address into the location as \\servername\desktop
    8. Sit back and relax.

    D
    That is how we do it here.

  6. Thanks to ICT_GUY from:

    andyturpie (28th May 2010)

  7. #4


    Join Date
    Mar 2009
    Location
    Leeds
    Posts
    3,490
    Thank Post
    134
    Thanked 472 Times in 411 Posts
    Rep Power
    149
    you could block it entirely with a script that just removed their access to %userprofile%\desktop on logon but that would stop shortcuts as well

    what about folder redirection to \\server\desktops\staff\%username% and then enabling a Quota of say 1mb

  8. #5

    Hightower's Avatar
    Join Date
    Jun 2008
    Location
    Cloud 9
    Posts
    4,920
    Thank Post
    493
    Thanked 688 Times in 443 Posts
    Rep Power
    237
    Quote Originally Posted by danrhodes View Post
    Why not use GP to redirect the Desktop to one central location on the server, apply NTFS ACL permissions to that folder so that staff can only read, this way you have controll over what is on their desktop from one central location, all the program shortcuts can either go on the desktop of a seperate re-directed startmenu.

    1. Edit user GPO
    2. Go to user config
    3. Go to folder redirection
    4. Right click folder redirection and click properties.
    5. Redirect all to same location
    6. Create a folder on your server, share is as "Desktop" and apply NTFS ACL's to give staff read permission.
    7. Enter the address into the location as \\servername\desktop
    8. Sit back and relax.

    D
    This is how I would do it too

  9. Thanks to Hightower from:

    andyturpie (28th May 2010)

  10. #6
    azrael78's Avatar
    Join Date
    Sep 2007
    Location
    Devon
    Posts
    383
    Thank Post
    47
    Thanked 37 Times in 33 Posts
    Rep Power
    16
    Quote Originally Posted by danrhodes View Post
    Why not use GP to redirect the Desktop to one central location on the server, apply NTFS ACL permissions to that folder so that staff can only read, this way you have controll over what is on their desktop from one central location, all the program shortcuts can either go on the desktop of a seperate re-directed startmenu.

    1. Edit user GPO
    2. Go to user config
    3. Go to folder redirection
    4. Right click folder redirection and click properties.
    5. Redirect all to same location
    6. Create a folder on your server, share is as "Desktop" and apply NTFS ACL's to give staff read permission.
    7. Enter the address into the location as \\servername\desktop
    8. Sit back and relax.

    D
    This + use FSRM if you are Server 2003R2/2008.
    You can then stop all kinds of files being saved on the desktop as well but still permit shortcuts, perhaps even throw a quota in there also?

    Az

  11. Thanks to azrael78 from:

    andyturpie (28th May 2010)

  12. #7
    danrhodes's Avatar
    Join Date
    Sep 2008
    Location
    Wath Upon Dearne
    Posts
    1,510
    Thank Post
    157
    Thanked 181 Times in 150 Posts
    Rep Power
    63
    Sounds like a good mix :-)

  13. #8

    nephilim's Avatar
    Join Date
    Nov 2008
    Location
    Bedfordshire
    Posts
    7,362
    Blog Entries
    2
    Thank Post
    921
    Thanked 1,033 Times in 790 Posts
    Rep Power
    448
    Quote Originally Posted by danrhodes View Post
    Why not use GP to redirect the Desktop to one central location on the server, apply NTFS ACL permissions to that folder so that staff can only read, this way you have controll over what is on their desktop from one central location, all the program shortcuts can either go on the desktop of a seperate re-directed startmenu.

    1. Edit user GPO
    2. Go to user config
    3. Go to folder redirection
    4. Right click folder redirection and click properties.
    5. Redirect all to same location
    6. Create a folder on your server, share is as "Desktop" and apply NTFS ACL's to give staff read permission.
    7. Enter the address into the location as \\servername\desktop
    8. Sit back and relax.

    D
    That's how I do it, and whilst I sit back and relax, I also listen to the complaints come rolling in about lost files etc, but I warn them that it is at their own detriment if they do not save it to the my documents folder like I tell them too!

  14. Thanks to nephilim from:

    andyturpie (28th May 2010)

  15. #9

    Join Date
    Jun 2009
    Location
    Watford
    Posts
    552
    Thank Post
    173
    Thanked 38 Times in 36 Posts
    Rep Power
    30
    Guys sounds like a plan, thanks again for your ideas - much appriciated

  16. #10
    danrhodes's Avatar
    Join Date
    Sep 2008
    Location
    Wath Upon Dearne
    Posts
    1,510
    Thank Post
    157
    Thanked 181 Times in 150 Posts
    Rep Power
    63
    No problem, that's what were here for :-)

SHARE:
+ Post New Thread

Similar Threads

  1. Replies: 5
    Last Post: 23rd June 2010, 07:04 PM
  2. Replies: 3
    Last Post: 26th May 2010, 03:38 PM
  3. sims slow to save data for some users
    By maark in forum MIS Systems
    Replies: 12
    Last Post: 2nd February 2010, 09:59 AM
  4. Replies: 0
    Last Post: 28th September 2009, 10:06 AM
  5. Replies: 2
    Last Post: 11th June 2008, 04:10 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •