Chunks_ Posted March 12, 2014 Posted March 12, 2014 Hi guys, I know this has been discussed a little on here in other threads but I couldn't really find a definitive answer so I hope you don't mind me posting this question again for further discussion. We currently have c: hidden and we have used the reg edit to remove the "create shortcut" in the context menu. (cant disable right click as it affects other programs). This is all good, however if they create a shortcut at home and bring it in on a memory stick they will still have access to c: Whats peoples thoughts on this and the best way to prevent this ? Cheers
Roberto Posted March 12, 2014 Posted March 12, 2014 My thought is that this is a losing game. Even if you lock this down all it takes is one of the apps you have to run to use a non-standard browsing tool to allow people to see the c:\ drive. Secure the c:\ drive properly using NTFS permissions (users only need to be able to write to their own user area), remember that there are (or should not be) any state secrets on there anyway, and get on with your day. That's what we do here and we've not had any problems.
Mr.Ben Posted March 12, 2014 Posted March 12, 2014 The best solution: Use GPO to hide the drive, but don't restrict access to it (it breaks the search functionality of the start menu). Ensure that your users are not running as admins and use GPO to hide and restrict access to folders that they do need in program files.
Chunks_ Posted March 12, 2014 Author Posted March 12, 2014 Its annoying cos all Microsoft would need to do is prevent the creation/use of shortcuts to hidden drives.... problem solved...
Roberto Posted March 12, 2014 Posted March 12, 2014 I honestly don't get what is so annoying about it. The students already know that your computers have a local hard drive installed with files on it. If they can change things you don't want them to change then the problem is that your permissions are set incorrectly, not that the students can see something they already know is there.
Steve21 Posted March 12, 2014 Posted March 12, 2014 Aye generally we don't bother. C's hidden for users, Permissions locked on it. Nothing they can do/touch/edit, that they couldn't run themselves anyway. Don't think you can physically lock the shortcut issue without a lot of permissions breaking stuff Steve
Darylrese Posted May 11, 2015 Posted May 11, 2015 Sorry to bring this one back up but I'm having the same issue at the moment. I have hidden C:\ from student accounts but they can still make a shortcut to C:\ and then see everything. Of course they only have read permissions BUT ABTutor stores screenshots taken by administrators on the local HDD so they can see when we are monitoring them! I have tried blocking .Ink in file in FSM on the file server but it doesn't work for .ink files....
TechMonkey Posted May 11, 2015 Posted May 11, 2015 I have tried blocking .Ink in file in FSM on the file server but it doesn't work for .ink files.... It will be .LNK, not I. Short for link. As other have said though why not use a GPP to remove student permission from that folder?
Darylrese Posted May 11, 2015 Posted May 11, 2015 How To Restrict Access To Drives In My Computer In Windows This solved it.
Chunks_ Posted May 11, 2015 Author Posted May 11, 2015 I honestly don't get what is so annoying about it. The students already know that your computers have a local hard drive installed with files on it. If they can change things you don't want them to change then the problem is that your permissions are set incorrectly, not that the students can see something they already know is there. Students gain access to C where they change the ease of access exe to the cmd exe. When they boot the machine they can then use the ease of access to actually open a command prompt and because no user has no logged on it has like system level rights and they can do lots of nasty things.
Darylrese Posted May 11, 2015 Posted May 11, 2015 Indeed its not a huge issue being able to read C:\ as my permissions are correct, but I'd prefer they had no access at all so this GPO has tidied things up a little.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now