Jump to content

Recommended Posts

Posted
You have to deny users access to c:\users\public\desktop.

 

You shouldn't have to :/

 

In our GPO I have a policy that redirects the desktop to a share I have created, the students have read only share and NTFS permissions and nothing else.

 

They are not the owner of any folders, they do not get the public desktop items and it just works.

 

I don't understand what is going wrong. Have you looked at the Group Policy logs on the client?

Posted
sounds like an issue i had a few years ago it was because in AD you still have a profile path for the students. so its combining both profile and redirected desktop
Posted
That's exactly how it is set here.

 

Could you also screenshot your advanced NTFS permissions for the folder and your share permissions on root of the share (\\FILESERVER\Data)?

 

Here is the folder:

Screen Shot 2016-05-12 at 7.43.40 AM.png

Posted
Here is the folder:

[ATTACH=CONFIG]36734[/ATTACH]

What about the folders below that? Are they inheriting permissions from Data?

 

I'd also check what HBPS has said too.

Posted

As far as I can see you have everything correct.

 

We apply permissions slight differently here, I have global and domain local groups and have a group for each share rather than user groups but it shouldn't really make any difference.

 

I'm sorry I can't be of much help :/

Posted
[ATTACH=CONFIG]36750[/ATTACH] here's my setup that works here

 

I changed my settings to match yours exactly, and I'm still seeing the local desktop and the redirected one.

Posted
ok had a quick google for you open the GPO for that user open user configuration > policies > administrative templates > Start Menu & task bar > and enable Remove common program groups from start menu..... this also covers what you need give it a try
Posted
Strange as it worked for me have you checked the client event logs after a gpupdate /force and relogged in
  • 1 month later...
Posted
Don't ask why, but I did yet another gpupdate this morning (probably the 5th) and it's now working.

 

I know i'm late to the convo and sorry for reviving a dead conversation too, but out of interest what is your refresh policy time set to? and do you apply any local GPO's like i have seen in some schools?

Posted

Im Sure classic shell needs to be enable with the users policy of your startup menu

 

Make sure that you can navigate to your folder through run on a desktop with permissions setup

 

Let me know if your still having issues

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...