zebwainwright Posted January 27, 2015 Posted January 27, 2015 So, my district is very antiquated and stuck in their ways. They have been using Deep Freeze forever as a crutch. I have been tasked with locking down student labs with Group Policy and have it almost all the way done except for one specific part. I need to prevent students from writing to the root of the C: drive. Here is what I have tried. The students are standard users, so they can't modify other parts of the C:\ but they can create folders and add files to the root. 1. I can hide the drives. This works, but they can still browse to the drive by typing in the path. Thus, they can still write to the root. 2. I can prevent access to the C:\ through GPO, which works, but here is the kicker....they must retain search functionality using the search box on the start menu. If I enable this policy, then programs like Word, Powerpoint, Chome don't show up. I would be ok with that, but the people in charge want this functionality. 3. I can not enable either policy, and go into the drives Properties > Security > Authenticated Users > Advanced > Change Permissions for Authenticated Users > Disallow Create Folders/Append Data and Create Files/Write Data ------->I can do this, but I am not sure if it will break anything, and also, I can't for the life of me figure out a way to script it. I find some articles on doing similar stuff in PowerShell but not for this exact scenario. And just so you can have some background info, currently every student in our district is using a generic login. no password. AND that generic accound is a local administrator. Getting rid of Deep Freeze has been such a battle. Our techs are worthless and don't know how to troubleshoot. thats why they like it. "Just reboot the computer." It's a crutch. My challenge is to basically give them a computer that functions as much like a normal computer as possible. I can lock down everything on the computer, but management won't allow that. The students are taught to search for their program in the start menu. We don't pin anything there. The theory is that we don't want to give them a dumbed down workstation because when they get out into the real world they will have full-blown access to their computer and won't know how to use it.....uhhhh hello???? Universities aren't going to give them full admin access!!!! And most likely their work won't either!!!! Sorry, but I feel like I am fighting with morons.....
woreilly Posted January 30, 2015 Posted January 30, 2015 Do you not have folder redirection for Desktop/Start Menu giving shortcuts to Office, Chrome, IE etc? If you do, I don't see why #2 would be a problem
zebwainwright Posted February 2, 2015 Author Posted February 2, 2015 Thanks for your reply. We were not planning on going that direction because of the amount of variables in the schools. I guess we could have many different redirected start menus and desktops, but our district has decided that they give every student a blank start menu and they can just search for their software. I might end up doing a start menu with 99 percent of the programs they need, and leave all programs so they can browse to anything else. They just wont be able to search.
clareq Posted February 2, 2015 Posted February 2, 2015 We put a folder on the c drive of each machine with the machine specific shortcuts, and redirect to that folder.
zebwainwright Posted February 2, 2015 Author Posted February 2, 2015 I think we might need to go that direction.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now