Jump to content

Recommended Posts

Posted

Cross posting from technet....

 

Hello,

 

The environment: about 100 users, about 25 Windows 7 PC, DC = Server 2003 SBS, AD, local profiles with redirected desktops, documents, start menus.

The special case: Some (generic) accounts are not supposed to be allowed to load media from external sources, such as flash drives. They must get their media from a server location.

The part of the solution I have: Using User GPO, you can block access to removable devices for these accounts. This works - flash drives, external cd roms, hard drives, etc do not open when using those accounts.

The issue: It is possible for a user who has external drive access to login, copy the files to his local profile on the HDD. Then it is possible for him to add the generic account that should not have access to the security permissions, allowing that generic account access to media they should not be able to access.

 

Does anyone have any way of preventing a user from adding anyone to their local profile on the HDD? As the user is a owner on their local profile, and the profile doesn't get created until they log in for the first time, they can change any permissions and add whoever they want in.

Please try to avoid a solution that runs a script after a user logs in and changes the permissions. We have 0 login scripts, everything done through group policy, and we want to stay that way if at all possible.

Thanks

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...