Jump to content

Restrict access to C: drive without breaking Start Menu search?


Recommended Posts

Posted

Just re-creating some old XP policies for Windows 7 but found a slightly annoying issue. Originally I set two policies:

 

Administrative Templates > Windows Components > Windows Explorer > Prevent access to Drives

Administrative Templates > Windows Components > Windows Explorer > Hide these specified Drives

 

With both enabled the Start Menu instant search no longer works :(

 

If I turn off the "Prevent" policy search works again but you can get access to the file system by creating a shortcut or copying one in from elsewhere. Any solutions to making the search worked in the locked-down configuration or is it a case of one or the other?

Posted

I'm also interested in knowing the answer to this... RM has C:\ hidden and unaccessable for everyone except sys admins.

 

Telling people to search for programs is [marginally] easier than telling them the folder paths. [You know what I mean...]

Posted
Redirect your Start Menu to a network location? I have C: drive restricted and hidden here, and the Start Menu redirected to a network location as standard practice, and I've not had any problems with it.
Posted
Only problem is the large variation in installed apps so lots of dead shortcuts. Also badly behaved apps fall over if the Start Menu location is read only, granted they can be repackaged using MSI generators etc but no time for that in the short term.
Posted
Only problem is the large variation in installed apps so lots of dead shortcuts. Also badly behaved apps fall over if the Start Menu location is read only, granted they can be repackaged using MSI generators etc but no time for that in the short term.

 

FWIW, dead shortcuts aren't a problem for us here - maybe that's just because people are used to not all software being everywhere, but in terms of the comptuer we've not had any technical issues arise from the inclusion of applications that are only present on some machines.

 

Badly behaved apps, though, well - that's just the fun & challenge of educational networks...

Posted

Still battling this, another one of those stupid design decisions that you wonder why no-one thought of:

 

Prevent access to C: drive... great but the sensible thing would be to include an exclusions list, of course that's far too logical and an all-or-nothing policy is much more useful so I either have to redirect the Downloads folder to the network or have it blocked by the policy if left in the local user profile :rolleyes:

Posted
this is just spitballing but could you redirect start menu to a network location but use gpp to copy the local start menu there then delete on logout
  • Thanks 1
Posted
this is just spitballing but could you redirect start menu to a network location but use gpp to copy the local start menu there then delete on logout

 

Interesting idea, might have a play with a logon script to try it out (on a Novell network so no GPP for me :p )

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...