Jump to content

Stop users saving to desktop (folder redirect - read only).


Recommended Posts

Posted

So near and yet so far...

 

I have given up trying to find a simple way of stopping the users saving files on the desktop and so I have started looking at folder redirection.

 

I have it up and running on a test user in a test OU using the following settings:

 

Created a Security Group with a test user in.

 

GPO configured:

 

Scope - Security Filtering (the security group I created as it failed without this - a lot of info out there doesn't mention this).

Delegation - Authenticated users, Admins, System and the security group I created.

 

User Configuration > Policies > Windows Settings > Folder Redirection

 

Desktop - Basic - Redirect everyone's folder to the same location

Target Folder Location - Create a folder for each user under the root path

Root Path - \\SERVER\HOMESHARE$\

 

Settings - Move the contents... (I have not ticked the 'Grant exclusive rights' as I read it causes issues with permissions)...

Policy Removal - Redirect the folder back (this doesn't seem to remove the folders in the share though)...

 

Although that part of it works well, I am unsure what steps I need to do now to make it read-only...

 

The only thing is, I have used their home folder to redirect to and due to that fact, the Desktop folder shows the 'user' as the 'owner'.

 

Can I now make the folder read-only for the owner?

 

Because I have also read that if the user is not the owner of the share, you must tick 'grant exclusive rights' or the redirection will fail...

 

Should I just create a seperate share for the folder redirection or try to change the properties of the folders inside the Home folders?

Posted

I'm not wholly sure what you're trying to do here.

As far as I can see, you want to give each user their own desktop that they can't change?

 

Why not just give everyone the same desktop (or have a couple of different ones based on job roles)? For example here we have:

Teachers > \\server\redirect$\desktop\Teaching_Staff

pupils > \\server\redirect$\desktop\Student

 

and so on with about 5 different desktops for finance, admin and so on.

 

If you want them each to have their own desktop folder then I'd go for a new share rather than messing with the home folders (I've really screwed up home folders by futzing with the permissions before).

  • Thanks 2
Posted

Why not just redirect the user's desktop to a folder in their home drive and leave it at that? Stops issues with profile growth and replication and is super easy to implement.

 

With that, there's no reason to stop users saving files on the desktop as they just end up in the home drive anyway!

  • Thanks 4
Posted
As far as I can see, you want to give each user their own desktop that they can't change?

 

This is just for students, but that's about the size of it. I thought folder redirection for the desktop folder and making it read-only was how you did it... No?

 

Why not just redirect the user's desktop to a folder in their home drive and leave it at that?!

 

The thing is that as we are a very small school with Early Years students and they all have a shared 'class' log on. This obviously means that they have a shared class home drive (but they have have their own folders within that). They have a local profile on the machine, so if they save to the desktop (or documents folders) that stays on the machine (half the time they don't even know where they have saved their stuff). It may work but I just see it as complicating matters if they have a 'Desktop' folder in there too.

Posted
The thing is that as we are a very small school with Early Years students and they all have a shared 'class' log on. This obviously means that they have a shared class home drive (but they have have their own folders within that). They have a local profile on the machine, so if they save to the desktop (or documents folders) that stays on the machine (half the time they don't even know where they have saved their stuff). It may work but I just see it as complicating matters if they have a 'Desktop' folder in there too.

If you redirect the Desktop to a folder under the home drive, nothing saved there will go to the local profile, solving the "staying-on-the-machine" issue. It doesn't solve the "files belong in the students' individual folders" issue, but then again there's nothing stopping them from just saving in the root of the home drive either.

 

It's a partial solution worth considering at least.

  • Thanks 1
Posted

If they can't change it, then why do they need on each?

 

I mean I've go everyone (or everyone in a specific group) redirected to the same (read only) folder so I can control the desktop icons centrally. Which IMO is the main reason for doing desktop redirect like that.

 

The main (or maybe only) reason to give everyone their own desktop would be so they can customise it. In which case FishCustard's Home drive solution is ideal.

Posted

Pt 2

 

Why not redirect the desktop to the root of the home drive. And the my documents, my pictures, my music. Then wherever they go it's the same place.

 

Sure you now have desktop full of "studentName" folders (which might be a GDPR issue), but it's a solution.

 

Or map to a random network share without the "make a folder for each user" option and make it read only. Then they can't save to the desktop and it's the same wherever they log in. Just make sure admin has access, so someone can update icons if required.

  • Thanks 1
Posted
We redirect the desktop to a folder in their home drive. That way their desktop will follow them around and they can use it as they wish, and those that like a clean desktop can keep it that way. We haven't advertised to staff that they can use the desktop, so only those who discover it themselves or ask us will know. Also stops us getting any aggro when the powers that be decide they want to use the desktop wallpaper as a billboard
  • Thanks 2
Posted

I redirect the desktop to a single desktop folder on the server. Any shortcuts I put in there all pupils get instantly, the folder security on the server is set to be read only for all pupils. Only me and my techie can put stuff in there. It works great, as we generally have the same software/shortcuts on all pupil pc's, they cant save anything to the desktop ever, and I can put shortcut or a folder or even a document on there and it takes 2 seconds to apply over 500 pcs.

 

I've got the same set up for teachers too, a dedicated teacher desktop folder shared with teacher shortcuts and useful links.

 

Works great!

  • Thanks 3
Posted

Sorry, a bit new to the folder redirection thing, so maybe my OP was a little vague or a little too verbose.

 

I have been trying to stop the children saving to the desktop, I've locked down as many GPOs as I can find but still cannot stop them doing it (only certain programs do it, they can't do it just through explorer or anything).

 

I redirect the desktop to a single desktop folder on the server. Any shortcuts I put in there all pupils get instantly, the folder security on the server is set to be read only for all pupils. Only me and my techie can put stuff in there. It works great, as we generally have the same software/shortcuts on all pupil pc's, they cant save anything to the desktop ever, and I can put shortcut or a folder or even a document on there and it takes 2 seconds to apply over 500 pcs.

 

I've got the same set up for teachers too, a dedicated teacher desktop folder shared with teacher shortcuts and useful links.

 

Works great!

 

Yes, this is what I'm looking for - just need a simple 'how to' really (what with permissions and all) after reading that if you don't tick the box for 'Grant exclusive rights' the folder redirection will not work - maybe I was getting confused as putting them in the home drive made them the owner of the folder... I doubt I would get away with locking down teacher desktops though...

 

We redirect the desktop to a folder in their home drive. That way their desktop will follow them around and they can use it as they wish, and those that like a clean desktop can keep it that way. We haven't advertised to staff that they can use the desktop, so only those who discover it themselves or ask us will know. Also stops us getting any aggro when the powers that be decide they want to use the desktop wallpaper as a billboard

 

As we have early years to Junior school age students I wanted something simple (it will only confuse them finding folders in their home drive for Desktop, Documents, Pictures etc.) and that would just give them more options to save their work in the wrong place (they have a folder with their name in their home drive).

 

Pt 2

 

Why not redirect the desktop to the root of the home drive. And the my documents, my pictures, my music. Then wherever they go it's the same place.

 

Sure you now have desktop full of "studentName" folders (which might be a GDPR issue), but it's a solution.

 

Or map to a random network share without the "make a folder for each user" option and make it read only. Then they can't save to the desktop and it's the same wherever they log in. Just make sure admin has access, so someone can update icons if required.

 

Yes, new share from scratch is probably the way to go (think I will just leave the home drive bit alone, so I don't have to worry about permissions being inherited or other conflicting GPOs), I just need to get my head around what to tick in the folder redirection GPO.

 

No worries about student names, not sure if GDPR is that strict? Anyway, as in my OP they have 'class' logons.

 

If you redirect the Desktop to a folder under the home drive, nothing saved there will go to the local profile, solving the "staying-on-the-machine" issue. It doesn't solve the "files belong in the students' individual folders" issue, but then again there's nothing stopping them from just saving in the root of the home drive either.

 

It's a partial solution worth considering at least.

 

I think I will go for a desktop folder share away from the home drives, I've got a load of GPOs keeping them away from all the other drives and at least if they save to the root of their home drive it is still there I guess. This was really just the last piece if the puzzle I hope, I thought I had locked down everything, but still kept finding random files on the desktop.

Posted

Well, predictably this didn't work for me....

 

Untitled.jpg

 

I kind of knew it wouldn't as it is a read-only folder!

 

Anybody care to share the GPO and share settings to get this working?

Posted

This is what we use for our Student desktop redirection. Enter the UNC path where its located, make sure the users only have 'Read' permissions in the Share properties, and only 'Read' in the Security section too and all should be good.

 

Annotation 2020-01-20 091847.jpg

  • Thanks 1
Posted
[ATTACH=CONFIG]56394[/ATTACH]

 

These are the settings we use, you would just need to change the share location to a location on a file server where the user groups have at least read access

 

This is what we use for our Student desktop redirection. Enter the UNC path where its located, make sure the users only have 'Read' permissions in the Share properties, and only 'Read' in the Security section too and all should be good.

 

[ATTACH=CONFIG]56395[/ATTACH]

 

Unfortunately I'm not redirecting the folders to their 'home drive' - it seems that only having 'read' permissions is stopping the user's log-on creating the folders.

Posted
We don't redirect to the Home Drive either, we have a dedicated folder which is then shared as read only and redirect to that. That way all students have the same desktop that they can't edit or save to. This is what you're trying to achieve isn't it?
Posted (edited)
Why would they need to create folders? I'm not sure what you're trying to achieve, if you want them to have a standard desktop which they can't modify, redirect the desktop to a server share with read only permissions using the Basic redirection. Or you use the advanced redirection, which is more or less the same except it will pick up a user group you have specified and redirect them based on that. Edited by ComboSmith
Posted
We don't redirect to the Home Drive either, we have a dedicated folder which is then shared as read only and redirect to that. That way all students have the same desktop that they can't edit or save to. This is what you're trying to achieve isn't it?

 

Yes, exactly that!

 

It just appears that it is failing to create the folders for some reason...

 

I'm thinking that when the user logs on, the folders are created in the user context, but as they only have 'read' permissions it fails.

 

EDIT: I may see the problem... I have the setting 'create a folder for each user under the root path' selected.

 

I will do some more testing...

Posted

Well, this is what I have and it is still not working... Can anyone see the issue?

 

GPO:

 

REDIRECTION_GPO_1.jpg

 

REDIRECTION_GPO_2.jpg

 

SHARE:

 

REDIRECTION 1.jpg

 

ADVANCED SHARING/PERMISSIONS:

 

REDIRECTION 2.jpg

 

SECURITY:

 

REDIRECTION 3.jpg

Posted

I don't think we have 'Move the Contents of the Desktop to the new location' ticked as per our policies. Maybe that is trying to write the desktop back to the share and falling over there?

 

Everything else looks good to me. You could change the REDIRECTION$ share advanced permissions to just 'Read' if you wanted to make sure they can't edit the share permissions.

Posted

In your second screenshot, I do not have Move contents of Deskop to the new location checked. My Policy Removal section is also set as Leave the folder in the new location when policy is removed.

 

My share permissions are: Everyone: Read. Domain Admins: Full Control.

My folder permissions are: Users: Read & Execute. Administrators, Domain Admins, SYSTEM are all inherited Full Control.

Posted

Please does this work on wins 10 version 1903?

 

I redirect the desktop to a single desktop folder on the server. Any shortcuts I put in there all pupils get instantly, the folder security on the server is set to be read only for all pupils. Only me and my techie can put stuff in there. It works great, as we generally have the same software/shortcuts on all pupil pc's, they cant save anything to the desktop ever, and I can put shortcut or a folder or even a document on there and it takes 2 seconds to apply over 500 pcs.

 

I've got the same set up for teachers too, a dedicated teacher desktop folder shared with teacher shortcuts and useful links.

 

Works great!

  • 2 weeks later...
Posted

Sorry to bump this, I have quite a few teachers saving all of their work to C:\Users\Wally\Desktop. I've warned them many times about this but they don't listen. I recently had one whose profile got wiped, all of the data got lost, and I had the old "I need these files nobody ever told me about this, all of my data should have been backed up" speil.

 

Problem is, now if I turn on folder redirection to their home folder (n:\desktop) - what would happen to the data in their current desktop?

When I enabled Folder Redirection when we used Win 7, we had nothing but problems - data in currently existing folders would just get deleted never to be seen again. Logons took 30+ minutes as it synced data - once I can understand, but it was trying to sync the complete contents of the folder every time the user logged on.

 

I set their desktops to "hidden" but this alone caused pandemonium as I have put useful shortcuts on the desktop, and a large majority of staff cannot access the programs any other way (start menu baffles them, serious).

Or should I just leave it as it is, send out a mass e-mail, and the next person who comes to me with a desktop query - print out that e-mail and tell them goodbye?

Posted
Problem is, now if I turn on folder redirection to their home folder (n:\desktop) - what would happen to the data in their current desktop?

 

It would still exist in the original location, you could still access it and copy it etc. There is a flag in the folder redirection settings to move contents to the new location, that should copy everything across for you

  • 7 months later...
Posted
Thanks for the note on correct GPO settings for redirect to a single Read only folder. Just set-up and tested with multiple student accounts and rolled live in total 30 mins :-)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...