Jump to content

Recommended Posts

Posted

Hi does anyone know of a policy to lock the desktop down i.e. stop pupils in an ou from saving to the desktop and also stop them from renaming desktop icons or sending them to deleted items.

 

Thanks in advance.

Posted

The desktop will (or should normally), be a redirected folder/share somewhere on your server. If you look at Group Policies you'll know for sure (Folder Redirection > Desktop).

 

Simply give Pupils read only access to the share, just as you would other folders on your network. Pupils will then be unable to save or rename shortcuts. They'll just see an Access Denied message.

Posted (edited)

Yes I see the folder... D:\data\profiles\Desktop\Pupil or \\server001\profiles\Desktop\Pupil

 

Permissions on the folder currently are...

 

Everyone: Full Control

CREATOR OWNER: Special Permissions

SYSTEM: Full Control

Administrators: Full Control (BPRU\Administrators) Full Control

Edited by cheekycharly
Posted

Remove Everyone: Full Control, then type/search: Authenticated Users, and specify Read/execute rights.

 

Then click Advanced > Change Permissions > Replace all child objects...

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...